CVE Vulnerability Database
Search and browse 386,783 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35290 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita... |
| CVE-2026-35287 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita... |
| CVE-2026-34316 | MEDIUM | 6.1 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). T... |
| CVE-2026-21954 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi... |
| CVE-2026-21953 | LOW | 3.3 | 0.1% | Jul 21, 2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi... |
| CVE-2026-16484 | HIGH | 7.3 | 0.4% | Jul 21, 2026 | A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2026-10680 | HIGH | 7.6 | 0.1% | Jul 21, 2026 | The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/class... |
| CVE-2026-10679 | MEDIUM | 5.5 | 0.1% | Jul 21, 2026 | The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config-... |
| CVE-2026-10678 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writ... |
| CVE-2026-10677 | MEDIUM | 6.5 | 0.1% | Jul 21, 2026 | The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied... |
| CVE-2026-10675 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the ... |
| CVE-2026-10674 | MEDIUM | 5.5 | 0.1% | Jul 21, 2026 | The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, cal... |
| CVE-2026-8983 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorizati... |
| CVE-2026-8982 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vend... |
| CVE-2026-65058 | MEDIUM | 5.9 | 0.3% | Jul 21, 2026 | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155... |
| CVE-2026-65057 | CRITICAL | 9.3 | 0.2% | Jul 21, 2026 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make... |
| CVE-2026-65056 | HIGH | 8.3 | 0.2% | Jul 21, 2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw... |
| CVE-2026-65055 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m... |
| CVE-2026-65054 | HIGH | 8.2 | 0.2% | Jul 21, 2026 | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media ... |
| CVE-2026-64881 | HIGH | 8.8 | 1.4% | Jul 21, 2026 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe... |
| CVE-2026-64822 | MEDIUM | 6.9 | 0.2% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi... |
| CVE-2026-64821 | MEDIUM | 5.3 | 0.1% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated... |
| CVE-2026-63764 | HIGH | 8.6 | 0.3% | Jul 21, 2026 | LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo... |
| CVE-2026-63358 | HIGH | 8.4 | 0.1% | Jul 21, 2026 | FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P... |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A ... |
