CVE Vulnerability Database
Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49092 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v... |
| CVE-2026-47671 | MEDIUM | 5.4 | 0.3% | Jul 21, 2026 | Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost c... |
| CVE-2026-47667 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i... |
| CVE-2026-46600 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| CVE-2026-46403 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithT... |
| CVE-2026-42397 | MEDIUM | 6.5 | 0.3% | Jul 21, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A... |
| CVE-2026-30632 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool. |
| CVE-2026-15957 | HIGH | 8.7 | 0.4% | Jul 21, 2026 | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface ... |
| CVE-2026-64877 | HIGH | 8.4 | 0.2% | Jul 21, 2026 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor... |
| CVE-2026-63454 | HIGH | 7.2 | 0.5% | Jul 21, 2026 | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an ... |
| CVE-2026-63453 | HIGH | 7.2 | 0.4% | Jul 21, 2026 | Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerab... |
| CVE-2026-59142 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and leng... |
| CVE-2026-59141 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices... |
| CVE-2026-59140 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the ra... |
| CVE-2026-59139 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and lengt... |
| CVE-2026-55084 | HIGH | 8.8 | — | Jul 21, 2026 | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL inje... |
| CVE-2026-55082 | HIGH | 8.7 | — | Jul 21, 2026 | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL ... |
| CVE-2026-55081 | HIGH | 7.3 | 0.3% | Jul 21, 2026 | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 ... |
| CVE-2026-16441 | CRITICAL | 9.6 | 0.3% | Jul 21, 2026 | In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been... |
| CVE-2026-12548 | MEDIUM | 4.2 | 0.4% | Jul 21, 2026 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw... |
| CVE-2026-12547 | LOW | 3.4 | — | Jul 21, 2026 | SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When th... |
| CVE-2016-20096 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows r... |
| CVE-2026-56583 | LOW | 3.1 | 0.1% | Jul 21, 2026 | HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h... |
| CVE-2026-56582 | LOW | 3.1 | 0.1% | Jul 21, 2026 | HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sen... |
| CVE-2026-56581 | LOW | 2.6 | 0.1% | Jul 21, 2026 | HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session ... |
