CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23572 | MEDIUM | 4.2 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as... |
| CVE-2024-23571 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying... |
| CVE-2024-23570 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an atta... |
| CVE-2024-23569 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header |
| CVE-2024-23568 | MEDIUM | 5.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th... |
| CVE-2024-23567 | MEDIUM | 4.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti... |
| CVE-2024-23566 | MEDIUM | 6.5 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead... |
| CVE-2024-23565 | MEDIUM | 5.3 | — | Jul 17, 2026 | HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism ... |
| CVE-2024-23564 | CRITICAL | 9.1 | — | Jul 17, 2026 | HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta... |
| CVE-2026-8396 | HIGH | 7.5 | — | Jul 17, 2026 | Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Dat... |
| CVE-2026-7189 | HIGH | 7.5 | — | Jul 17, 2026 | Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessin... |
| CVE-2026-16014 | HIGH | 7.3 | 0.3% | Jul 17, 2026 | A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the compo... |
| CVE-2026-13410 | HIGH | 8.2 | 0.2% | Jul 17, 2026 | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is in... |
| CVE-2026-13082 | MEDIUM | 5.3 | — | Jul 17, 2026 | GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge ... |
| CVE-2026-16013 | MEDIUM | 5.5 | — | Jul 17, 2026 | A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this is... |
| CVE-2026-16009 | MEDIUM | 6.3 | — | Jul 17, 2026 | A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file... |
| CVE-2026-15943 | MEDIUM | 5.5 | 0.2% | Jul 17, 2026 | A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The is... |
| CVE-2026-9602 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the D... |
| CVE-2026-8075 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Matter... |
| CVE-2026-59695 | HIGH | 8.3 | — | Jul 17, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f... |
| CVE-2026-59694 | HIGH | 8.3 | — | Jul 17, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the... |
| CVE-2026-59252 | HIGH | 8.2 | — | Jul 17, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f... |
| CVE-2026-16008 | MEDIUM | 6.3 | — | Jul 17, 2026 | A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parseP... |
| CVE-2026-22104 | HIGH | 7.1 | 0.3% | Jul 17, 2026 | Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows... |
| CVE-2026-62764 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user... |
