CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47088 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi... |
| CVE-2026-47087 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A... |
| CVE-2026-47086 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe... |
| CVE-2026-47085 | MEDIUM | 4 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk... |
| CVE-2026-47084 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut... |
| CVE-2026-47083 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u... |
| CVE-2026-47082 | MEDIUM | 5.4 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-ma... |
| CVE-2026-47081 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac... |
| CVE-2026-46515 | CRITICAL | 9.3 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call ... |
| CVE-2026-46514 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword... |
| CVE-2026-46513 | HIGH | 7.4 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T... |
| CVE-2026-46512 | CRITICAL | 9.9 | 0.4% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para... |
| CVE-2026-46404 | MEDIUM | 6.8 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res... |
| CVE-2026-46378 | MEDIUM | 6.2 | 0.1% | Jul 16, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-46377 | MEDIUM | 6.2 | 0.1% | Jul 16, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-46353 | HIGH | 8.1 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a... |
| CVE-2026-46351 | HIGH | 8.1 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit... |
| CVE-2026-46338 | MEDIUM | 4.3 | 0.3% | Jul 16, 2026 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.... |
| CVE-2026-46687 | HIGH | 7.7 | 0.3% | Jul 16, 2026 | Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t... |
| CVE-2026-46686 | HIGH | 8.5 | 0.3% | Jul 16, 2026 | Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword p... |
| CVE-2026-46341 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation... |
| CVE-2026-46336 | HIGH | 7.1 | 0.3% | Jul 16, 2026 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ... |
| CVE-2026-45336 | CRITICAL | 10 | 0.4% | Jul 16, 2026 | HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring ... |
| CVE-2026-44970 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call... |
| CVE-2026-44969 | LOW | 3.3 | 0.1% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/... |
