CVE Vulnerability Database
Search and browse 389,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38752 | LOW | 2.9 | 0.3% | Jul 15, 2026 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial ... |
| CVE-2026-36590 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in... |
| CVE-2026-30623 | CRITICAL | 9.8 | 0.3% | Jul 15, 2026 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application... |
| CVE-2026-30618 | CRITICAL | 9.8 | 0.6% | Jul 15, 2026 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution... |
| CVE-2026-26719 | MEDIUM | 6.1 | 0.4% | Jul 15, 2026 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra... |
| CVE-2026-26718 | CRITICAL | 9.1 | 0.3% | Jul 15, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att... |
| CVE-2026-15921 | LOW | 3.1 | 0.2% | Jul 15, 2026 | Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.... |
| CVE-2025-65720 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user... |
| CVE-2026-62361 | MEDIUM | 5.5 | 0.2% | Jul 15, 2026 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib... |
| CVE-2026-62312 | HIGH | 8.8 | 0.7% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra... |
| CVE-2026-59950 | HIGH | 8.1 | 0.2% | Jul 15, 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,... |
| CVE-2026-56679 | HIGH | 8.7 | 0.3% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t... |
| CVE-2026-56678 | MEDIUM | 6.4 | 0.2% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key... |
| CVE-2026-55608 | MEDIUM | 5.4 | 0.3% | Jul 15, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-55410 | MEDIUM | 6.7 | 0.4% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-55399 | MEDIUM | 4.3 | 0.2% | Jul 15, 2026 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali... |
| CVE-2026-55398 | LOW | 3.7 | 0.3% | Jul 15, 2026 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with ... |
| CVE-2026-54052 | CRITICAL | 9.9 | 0.4% | Jul 15, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-52888 | MEDIUM | 6.8 | 0.3% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.... |
| CVE-2026-52887 | CRITICAL | 10 | 0.6% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-51380 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of S... |
| CVE-2026-49353 | HIGH | 7.5 | 0.4% | Jul 15, 2026 | 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate use... |
| CVE-2026-49352 | CRITICAL | 9.8 | 0.6% | Jul 15, 2026 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-... |
| CVE-2026-46339 | CRITICAL | 10 | 4.6% | Jul 15, 2026 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/... |
| CVE-2026-38753 | MEDIUM | 4.9 | 0.3% | Jul 15, 2026 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv... |
