CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48010 | MEDIUM | 6.5 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framewo... |
| CVE-2026-48009 | MEDIUM | 6.8 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:re... |
| CVE-2026-48008 | MEDIUM | 6.5 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL... |
| CVE-2025-59866 | LOW | 3.3 | — | Jul 17, 2026 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es... |
| CVE-2026-9588 | HIGH | 7 | — | Jul 17, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicem... |
| CVE-2026-9587 | HIGH | 7.1 | — | Jul 17, 2026 | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file ... |
| CVE-2026-9586 | CRITICAL | 9.8 | 1.1% | Jul 17, 2026 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint pr... |
| CVE-2026-9585 | HIGH | 8.6 | — | Jul 17, 2026 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.... |
| CVE-2026-8297 | CRITICAL | 9.8 | — | Jul 17, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En... |
| CVE-2026-63309 | MEDIUM | 4.3 | — | Jul 17, 2026 | SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to... |
| CVE-2026-63308 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help... |
| CVE-2026-63307 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{i... |
| CVE-2026-63101 | HIGH | 8.7 | — | Jul 17, 2026 | Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t... |
| CVE-2026-57860 | HIGH | 7.8 | — | Jul 17, 2026 | ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i... |
| CVE-2026-54496 | CRITICAL | 9.3 | — | Jul 17, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit... |
| CVE-2026-49216 | MEDIUM | 5.4 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/... |
| CVE-2026-49215 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventList... |
| CVE-2026-49212 | HIGH | 7.5 | 0.2% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\Liv... |
| CVE-2026-49211 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\En... |
| CVE-2026-49210 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\Child... |
| CVE-2026-49209 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller... |
| CVE-2026-49208 | MEDIUM | 5.3 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date... |
| CVE-2026-44722 | MEDIUM | 6.2 | — | Jul 17, 2026 | pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python... |
| CVE-2026-21764 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric... |
| CVE-2026-21762 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag... |
