CVE Vulnerability Database
Search and browse 386,644 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65058 | MEDIUM | 5.9 | 0.3% | Jul 21, 2026 | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155... |
| CVE-2026-65057 | CRITICAL | 9.3 | 0.2% | Jul 21, 2026 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make... |
| CVE-2026-65056 | HIGH | 8.3 | 0.2% | Jul 21, 2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw... |
| CVE-2026-65055 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m... |
| CVE-2026-65054 | HIGH | 8.2 | 0.2% | Jul 21, 2026 | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media ... |
| CVE-2026-64881 | HIGH | 8.8 | 1.4% | Jul 21, 2026 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe... |
| CVE-2026-64822 | MEDIUM | 6.9 | 0.2% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi... |
| CVE-2026-64821 | MEDIUM | 5.3 | 0.1% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated... |
| CVE-2026-63764 | HIGH | 8.6 | 0.3% | Jul 21, 2026 | LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo... |
| CVE-2026-63358 | HIGH | 8.4 | 0.1% | Jul 21, 2026 | FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P... |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A ... |
| CVE-2026-63139 | MEDIUM | 6.5 | 0.3% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)... |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-63092 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a... |
| CVE-2026-63080 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authe... |
| CVE-2026-56147 | HIGH | 7.1 | 0.3% | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and... |
| CVE-2026-52476 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage... |
| CVE-2026-52475 | MEDIUM | 6.1 | 0.2% | Jul 21, 2026 | Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the ... |
| CVE-2026-52474 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file. |
| CVE-2026-52472 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml ... |
| CVE-2026-52470 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper... |
| CVE-2026-52469 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.... |
| CVE-2026-47714 | MEDIUM | 6.1 | 0.1% | Jul 21, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code i... |
| CVE-2026-47708 | CRITICAL | 9.3 | 0.3% | Jul 21, 2026 | MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` ... |
| CVE-2026-47697 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). ... |
