CVE Vulnerability Database
Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32819 | MEDIUM | 4.3 | 0.2% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32806 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-16312 | — | — | — | Jul 20, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-6793 | MEDIUM | 5.4 | — | Jul 20, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering ... |
| CVE-2026-63429 | HIGH | 8.6 | 0.3% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no ... |
| CVE-2026-63428 | MEDIUM | 5.8 | 0.2% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,... |
| CVE-2026-63102 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitr... |
| CVE-2026-51027 | CRITICAL | 9.9 | 0.3% | Jul 20, 2026 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. |
| CVE-2026-51026 | MEDIUM | 6.5 | 0.8% | Jul 20, 2026 | Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a ... |
| CVE-2026-48824 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2... |
| CVE-2026-46671 | MEDIUM | 4.4 | 0.1% | Jul 20, 2026 | Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciou... |
| CVE-2026-46428 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug ... |
| CVE-2026-46415 | HIGH | 8.2 | 0.2% | Jul 20, 2026 | The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the clien... |
| CVE-2026-46412 | CRITICAL | 10 | 0.4% | Jul 20, 2026 | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support... |
| CVE-2026-45797 | MEDIUM | 6.4 | 0.4% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated f... |
| CVE-2026-45713 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M... |
| CVE-2026-45712 | MEDIUM | 5.9 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat... |
| CVE-2026-45711 | HIGH | 8.2 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou... |
| CVE-2026-45709 | MEDIUM | 5.8 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R... |
| CVE-2026-35198 | CRITICAL | 9 | 0.2% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i... |
| CVE-2026-32822 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32807 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-28220 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i... |
| CVE-2026-27823 | HIGH | 8.7 | 1.0% | Jul 20, 2026 | A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an auth... |
| CVE-2026-26199 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`... |
