CVE Vulnerability Database
Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12701 | CRITICAL | 9 | — | Jul 20, 2026 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa... |
| CVE-2026-57311 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP... |
| CVE-2026-57310 | MEDIUM | 6.3 | 0.2% | Jul 20, 2026 | Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker... |
| CVE-2026-57309 | CRITICAL | 9.3 | 0.3% | Jul 20, 2026 | A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to injec... |
| CVE-2026-16248 | HIGH | 8.8 | — | Jul 20, 2026 | A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the ... |
| CVE-2026-16244 | MEDIUM | 6.3 | — | Jul 20, 2026 | A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit... |
| CVE-2026-12080 | HIGH | 7.3 | 0.2% | Jul 20, 2026 | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a... |
| CVE-2026-64623 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the... |
| CVE-2026-64622 | CRITICAL | 9.3 | 0.4% | Jul 20, 2026 | Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/... |
| CVE-2026-64621 | CRITICAL | 9.3 | 0.2% | Jul 20, 2026 | FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl... |
| CVE-2026-64620 | CRITICAL | 9.1 | 0.6% | Jul 20, 2026 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypt... |
| CVE-2026-63763 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg... |
| CVE-2026-63762 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript... |
| CVE-2026-63761 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES... |
| CVE-2026-63760 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin... |
| CVE-2026-63759 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot... |
| CVE-2026-63758 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenti... |
| CVE-2026-63757 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at... |
| CVE-2026-63756 | CRITICAL | 9.2 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows... |
| CVE-2026-63755 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i... |
| CVE-2026-63754 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause... |
| CVE-2026-63753 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At... |
| CVE-2026-63752 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated ... |
| CVE-2026-63751 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo... |
| CVE-2026-63750 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c... |
