CVE Vulnerability Database
Search and browse 386,702 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10680 | HIGH | 7.6 | 0.1% | Jul 21, 2026 | The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/class... |
| CVE-2026-10679 | MEDIUM | 5.5 | 0.1% | Jul 21, 2026 | The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config-... |
| CVE-2026-10678 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writ... |
| CVE-2026-10677 | MEDIUM | 6.5 | 0.1% | Jul 21, 2026 | The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied... |
| CVE-2026-10675 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the ... |
| CVE-2026-10674 | MEDIUM | 5.5 | 0.1% | Jul 21, 2026 | The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, cal... |
| CVE-2026-8983 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorizati... |
| CVE-2026-8982 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vend... |
| CVE-2026-65058 | MEDIUM | 5.9 | 0.3% | Jul 21, 2026 | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155... |
| CVE-2026-65057 | CRITICAL | 9.3 | 0.2% | Jul 21, 2026 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make... |
| CVE-2026-65056 | HIGH | 8.3 | 0.2% | Jul 21, 2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw... |
| CVE-2026-65055 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m... |
| CVE-2026-65054 | HIGH | 8.2 | 0.2% | Jul 21, 2026 | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media ... |
| CVE-2026-64881 | HIGH | 8.8 | 1.4% | Jul 21, 2026 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe... |
| CVE-2026-64822 | MEDIUM | 6.9 | 0.2% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi... |
| CVE-2026-64821 | MEDIUM | 5.3 | 0.1% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated... |
| CVE-2026-63764 | HIGH | 8.6 | 0.3% | Jul 21, 2026 | LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo... |
| CVE-2026-63358 | HIGH | 8.4 | 0.1% | Jul 21, 2026 | FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P... |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A ... |
| CVE-2026-63139 | MEDIUM | 6.5 | 0.3% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)... |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-63092 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a... |
| CVE-2026-63080 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authe... |
| CVE-2026-56147 | HIGH | 7.1 | 0.3% | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and... |
| CVE-2026-52476 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage... |
