CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51677 | CRITICAL | 9.1 | 0.4% | Jul 17, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12... |
| CVE-2026-9171 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ... |
| CVE-2026-9135 | CRITICAL | 9.9 | 0.8% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co... |
| CVE-2026-9103 | CRITICAL | 9.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti... |
| CVE-2026-58195 | HIGH | 8.8 | 0.5% | Jul 17, 2026 | Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone... |
| CVE-2026-53712 | HIGH | 8.2 | 0.3% | Jul 17, 2026 | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L... |
| CVE-2026-52746 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toM... |
| CVE-2026-50185 | LOW | 3.3 | 0.1% | Jul 17, 2026 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-... |
| CVE-2026-49835 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middle... |
| CVE-2026-48487 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a... |
| CVE-2026-48045 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_que... |
| CVE-2026-47184 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inser... |
| CVE-2026-47183 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exceptio... |
| CVE-2026-47180 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_label... |
| CVE-2026-45703 | MEDIUM | 6.4 | 0.2% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport expor... |
| CVE-2026-45309 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to... |
| CVE-2026-45162 | HIGH | 8 | 0.6% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc... |
| CVE-2026-16073 | LOW | 3.5 | 0.2% | Jul 17, 2026 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S... |
| CVE-2026-9762 | HIGH | 7.8 | 0.2% | Jul 17, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under u... |
| CVE-2026-9202 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow... |
| CVE-2026-9198 | CRITICAL | 9.8 | 17.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER toke... |
| CVE-2026-50273 | HIGH | 7.5 | — | Jul 17, 2026 | Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing librarie... |
| CVE-2026-48016 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment... |
| CVE-2026-48015 | MEDIUM | 4.9 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelis... |
| CVE-2026-48014 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action... |
