CVE Vulnerability Database
Search and browse 386,272 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13066 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i... |
| CVE-2026-13065 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator... |
| CVE-2026-13064 | HIGH | 7.1 | 0.4% | Jul 22, 2026 | Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in ... |
| CVE-2026-13063 | MEDIUM | 5.3 | 0.4% | Jul 22, 2026 | An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem... |
| CVE-2026-13062 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal ... |
| CVE-2026-13061 | MEDIUM | 5.3 | 0.2% | Jul 22, 2026 | An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi... |
| CVE-2026-13060 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | An authenticated user with limited read privileges may be able to access documents from collections they are not authori... |
| CVE-2026-13059 | HIGH | 8.6 | 0.3% | Jul 22, 2026 | An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role... |
| CVE-2026-13058 | MEDIUM | 6.5 | 0.2% | Jul 22, 2026 | An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf... |
| CVE-2026-13057 | MEDIUM | 6.5 | 0.3% | Jul 22, 2026 | An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In... |
| CVE-2026-13056 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object... |
| CVE-2026-13055 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)... |
| CVE-2026-3482 | MEDIUM | 5.3 | 0.3% | Jul 22, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.... |
| CVE-2026-22049 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnera... |
| CVE-2026-16624 | CRITICAL | 9.6 | 0.2% | Jul 22, 2026 | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on... |
| CVE-2026-65650 | MEDIUM | 4.3 | — | Jul 22, 2026 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. |
| CVE-2026-64835 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within l... |
| CVE-2026-64834 | HIGH | 8.7 | 0.5% | Jul 22, 2026 | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp... |
| CVE-2026-64833 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attacker... |
| CVE-2026-64832 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavc... |
| CVE-2026-16157 | HIGH | 7.8 | 0.1% | Jul 22, 2026 | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In... |
| CVE-2026-7328 | MEDIUM | 6.8 | — | Jul 22, 2026 | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM... |
| CVE-2026-65013 | HIGH | 8.8 | 0.5% | Jul 22, 2026 | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a... |
| CVE-2026-65012 | MEDIUM | 6.3 | 0.4% | Jul 22, 2026 | InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo... |
| CVE-2026-65011 | MEDIUM | 5.3 | 0.4% | Jul 22, 2026 | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de... |
