CVE Vulnerability Database
Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26197 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor... |
| CVE-2026-26081 | MEDIUM | 4.8 | 0.5% | Jul 20, 2026 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise... |
| CVE-2026-26080 | LOW | 3.7 | 0.5% | Jul 20, 2026 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro... |
| CVE-2026-25039 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit... |
| CVE-2026-21824 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso... |
| CVE-2026-13724 | MEDIUM | 4.3 | 0.2% | Jul 20, 2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an... |
| CVE-2026-63091 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r... |
| CVE-2026-63090 | HIGH | 8.8 | 0.5% | Jul 20, 2026 | ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo... |
| CVE-2026-63071 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements... |
| CVE-2026-62418 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Reso... |
| CVE-2026-62183 | CRITICAL | 9.8 | 0.3% | Jul 20, 2026 | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure... |
| CVE-2026-59238 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderA... |
| CVE-2026-57308 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A... |
| CVE-2026-54910 | HIGH | 7.7 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` ... |
| CVE-2026-54685 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a... |
| CVE-2026-53421 | CRITICAL | 9.8 | 0.5% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen... |
| CVE-2026-53405 | CRITICAL | 9.8 | 0.3% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements... |
| CVE-2026-52349 | HIGH | 7.8 | 0.3% | Jul 20, 2026 | Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a... |
| CVE-2026-51386 | — | — | — | Jul 20, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate ... |
| CVE-2026-46516 | MEDIUM | 4.8 | 0.3% | Jul 20, 2026 | Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js... |
| CVE-2026-46410 | HIGH | 8.7 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may le... |
| CVE-2026-45270 | HIGH | 8.7 | 0.2% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module... |
| CVE-2026-45139 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo... |
| CVE-2026-16277 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin... |
| CVE-2026-16252 | HIGH | 7.3 | — | Jul 20, 2026 | A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System ... |
