CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63306 | CRITICAL | 9.2 | — | Jul 16, 2026 | stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e... |
| CVE-2026-63305 | CRITICAL | 9.2 | 1.4% | Jul 16, 2026 | AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and ... |
| CVE-2026-63304 | CRITICAL | 9.2 | 1.4% | Jul 16, 2026 | AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list... |
| CVE-2026-12391 | MEDIUM | 5 | — | Jul 16, 2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with... |
| CVE-2026-11386 | CRITICAL | 9 | — | Jul 16, 2026 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).... |
| CVE-2025-71388 | HIGH | 7.6 | 0.3% | Jul 16, 2026 | stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ... |
| CVE-2025-71377 | HIGH | 8.7 | 0.4% | Jul 16, 2026 | stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me... |
| CVE-2024-58360 | MEDIUM | 6.9 | 0.3% | Jul 16, 2026 | stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verifica... |
| CVE-2026-59249 | MEDIUM | 6.3 | — | Jul 16, 2026 | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malici... |
| CVE-2026-35149 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us... |
| CVE-2026-35148 | MEDIUM | 6.3 | 0.2% | Jul 16, 2026 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar... |
| CVE-2026-35147 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif... |
| CVE-2026-35146 | MEDIUM | 6.3 | 0.1% | Jul 16, 2026 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn... |
| CVE-2023-49900 | CRITICAL | 9.8 | — | Jul 16, 2026 | An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in t... |
| CVE-2023-49899 | CRITICAL | 9.8 | 0.2% | Jul 16, 2026 | An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the ori... |
| CVE-2026-22752 | CRITICAL | 9.6 | 0.5% | Jul 16, 2026 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe... |
| CVE-2026-7543 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions ... |
| CVE-2026-6424 | MEDIUM | 6.7 | 0.1% | Jul 16, 2026 | Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the syste... |
| CVE-2026-6423 | HIGH | 8.5 | 0.1% | Jul 16, 2026 | A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authenti... |
| CVE-2026-58078 | HIGH | 8.7 | 0.2% | Jul 16, 2026 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio... |
| CVE-2026-15727 | MEDIUM | 4.9 | — | Jul 16, 2026 | The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in ... |
| CVE-2026-15651 | MEDIUM | 4.9 | 0.3% | Jul 16, 2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para... |
| CVE-2026-15610 | MEDIUM | 4.3 | — | Jul 16, 2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio... |
| CVE-2026-15407 | MEDIUM | 4.3 | 0.3% | Jul 16, 2026 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7... |
| CVE-2026-15350 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.... |
