CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44968 | MEDIUM | 6.3 | 0.1% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/... |
| CVE-2026-15945 | LOW | 2.7 | 0.2% | Jul 16, 2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin ... |
| CVE-2026-15737 | MEDIUM | 5.7 | 0.2% | Jul 16, 2026 | AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t... |
| CVE-2021-27137 | HIGH | 8.1 | 5.4% | Jul 16, 2026 | An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling function... |
| CVE-2026-9046 | HIGH | 7.3 | — | Jul 16, 2026 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications... |
| CVE-2026-6511 | MEDIUM | 6.8 | — | Jul 16, 2026 | During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart... |
| CVE-2026-63088 | HIGH | 8.6 | — | Jul 16, 2026 | stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-... |
| CVE-2026-63087 | CRITICAL | 9.8 | 0.4% | Jul 16, 2026 | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a... |
| CVE-2026-63086 | HIGH | 8.6 | — | Jul 16, 2026 | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat... |
| CVE-2026-63085 | HIGH | 8.8 | 0.4% | Jul 16, 2026 | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticate... |
| CVE-2026-57074 | CRITICAL | 9.1 | 0.2% | Jul 16, 2026 | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to ... |
| CVE-2026-57073 | CRITICAL | 9.1 | — | Jul 16, 2026 | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to... |
| CVE-2026-55548 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr... |
| CVE-2026-55407 | MEDIUM | 6.3 | — | Jul 16, 2026 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the dec... |
| CVE-2026-55406 | MEDIUM | 5.9 | — | Jul 16, 2026 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a sound... |
| CVE-2026-50012 | MEDIUM | 5.5 | 2.3% | Jul 16, 2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli... |
| CVE-2026-47751 | MEDIUM | 5.3 | 0.4% | Jul 16, 2026 | Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to... |
| CVE-2026-47729 | MEDIUM | 6.5 | 1.9% | Jul 16, 2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in t... |
| CVE-2026-46621 | CRITICAL | 9.1 | 0.7% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica... |
| CVE-2026-46562 | CRITICAL | 9.8 | 0.6% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip... |
| CVE-2026-45795 | MEDIUM | 5.3 | — | Jul 16, 2026 | The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac... |
| CVE-2026-45612 | MEDIUM | 5.5 | — | Jul 16, 2026 | rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can... |
| CVE-2026-45576 | HIGH | 7.5 | 0.4% | Jul 16, 2026 | zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores at... |
| CVE-2026-45568 | CRITICAL | 9.1 | 0.4% | Jul 16, 2026 | zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Fl... |
| CVE-2026-45367 | HIGH | 7.5 | 0.5% | Jul 16, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7,... |
