CVE Vulnerability Database
Search and browse 389,948 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40954 | LOW | 3.7 | 0.2% | Jul 15, 2026 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 1... |
| CVE-2026-40953 | MEDIUM | 4.4 | 0.1% | Jul 15, 2026 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers... |
| CVE-2026-40952 | HIGH | 7.8 | 0.1% | Jul 15, 2026 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to... |
| CVE-2026-33443 | MEDIUM | 5.9 | 0.2% | Jul 15, 2026 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg... |
| CVE-2026-62947 | MEDIUM | 4.9 | 0.4% | Jul 15, 2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io aut... |
| CVE-2026-62355 | MEDIUM | 5.4 | — | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea... |
| CVE-2026-62353 | MEDIUM | 5.4 | — | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p... |
| CVE-2026-62351 | HIGH | 7.5 | — | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/sr... |
| CVE-2026-62350 | HIGH | 7.2 | 0.4% | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit... |
| CVE-2026-62349 | HIGH | 8.3 | — | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, sourc... |
| CVE-2026-62348 | MEDIUM | 5.4 | 0.2% | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allo... |
| CVE-2026-54443 | MEDIUM | 5.9 | — | Jul 15, 2026 | Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF... |
| CVE-2026-49988 | MEDIUM | 5.5 | 0.1% | Jul 15, 2026 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_... |
| CVE-2026-49987 | HIGH | 8.8 | 0.5% | Jul 15, 2026 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitSha... |
| CVE-2026-46485 | HIGH | 8.2 | 0.3% | Jul 15, 2026 | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user... |
| CVE-2026-46421 | CRITICAL | 9.3 | — | Jul 15, 2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d... |
| CVE-2026-26032 | MEDIUM | 5.4 | — | Jul 15, 2026 | The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a... |
| CVE-2026-15895 | HIGH | 8.4 | — | Jul 15, 2026 | OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent ... |
| CVE-2026-15746 | MEDIUM | 6.9 | — | Jul 15, 2026 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide... |
| CVE-2026-12997 | HIGH | 7.5 | — | Jul 15, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4... |
| CVE-2026-8055 | — | — | — | Jul 15, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a ... |
| CVE-2026-62948 | CRITICAL | 9.6 | 0.3% | Jul 15, 2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN opt... |
| CVE-2026-62389 | — | — | 0.4% | Jul 15, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate of CVE-2026-48... |
| CVE-2026-61643 | MEDIUM | 5.9 | 0.2% | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can... |
| CVE-2026-59258 | HIGH | 8.3 | — | Jul 15, 2026 | immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that all... |
