CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7754 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa... |
| CVE-2026-7667 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacke... |
| CVE-2026-7364 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident... |
| CVE-2026-63030 | CRITICAL | 9.8 | 38.6% | Jul 17, 2026 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which... |
| CVE-2026-60137 | MEDIUM | 5.9 | 78.0% | Jul 17, 2026 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p... |
| CVE-2026-55254 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src... |
| CVE-2026-54465 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to im... |
| CVE-2026-54464 | MEDIUM | 6.3 | 0.4% | Jul 17, 2026 | ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can ... |
| CVE-2026-54463 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket pro... |
| CVE-2026-54171 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip add... |
| CVE-2026-52199 | CRITICAL | 9.1 | 0.6% | Jul 17, 2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/... |
| CVE-2026-51833 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can ... |
| CVE-2026-50289 | HIGH | 8.8 | 1.1% | Jul 17, 2026 | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is v... |
| CVE-2026-50197 | HIGH | 7.8 | 0.5% | Jul 17, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent... |
| CVE-2026-50163 | HIGH | 7.1 | 0.4% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 vali... |
| CVE-2026-50162 | MEDIUM | 6.9 | 0.5% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a le... |
| CVE-2026-50151 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completeP... |
| CVE-2026-4942 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Tran... |
| CVE-2026-4938 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident... |
| CVE-2026-49852 | HIGH | 8.7 | 0.2% | Jul 17, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-49834 | HIGH | 7.5 | 0.1% | Jul 17, 2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransp... |
| CVE-2026-49284 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSA... |
| CVE-2026-48978 | LOW | 2.1 | 0.3% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's ... |
| CVE-2026-48819 | MEDIUM | 4.8 | 0.4% | Jul 17, 2026 | Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/pa... |
| CVE-2026-48504 | MEDIUM | 5.3 | 0.4% | Jul 17, 2026 | OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont... |
