CVE Vulnerability Database
Search and browse 389,949 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15804 | HIGH | 8.8 | 0.3% | Jul 15, 2026 | The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands ... |
| CVE-2026-15583 | HIGH | 8.6 | 0.3% | Jul 15, 2026 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro... |
| CVE-2026-14251 | HIGH | 7.7 | 0.2% | Jul 15, 2026 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when ... |
| CVE-2026-42936 | HIGH | 8.4 | 0.1% | Jul 15, 2026 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory wh... |
| CVE-2026-12512 | HIGH | 8.6 | 0.2% | Jul 15, 2026 | The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before us... |
| CVE-2026-12281 | HIGH | 8.1 | 0.1% | Jul 15, 2026 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without ... |
| CVE-2026-11580 | MEDIUM | 5.5 | 0.1% | Jul 15, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab... |
| CVE-2026-11579 | MEDIUM | 5.3 | 0.2% | Jul 15, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload ... |
| CVE-2026-8920 | HIGH | 8.5 | 0.1% | Jul 15, 2026 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa... |
| CVE-2026-8919 | HIGH | 7.2 | 0.3% | Jul 15, 2026 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local us... |
| CVE-2026-15030 | MEDIUM | 5.6 | 0.1% | Jul 15, 2026 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows ... |
| CVE-2026-15029 | HIGH | 8.4 | 0.1% | Jul 15, 2026 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Mana... |
| CVE-2026-13585 | HIGH | 8.2 | 0.1% | Jul 15, 2026 | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in ... |
| CVE-2026-13385 | CRITICAL | 9.5 | 0.1% | Jul 15, 2026 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows... |
| CVE-2026-11851 | MEDIUM | 5.9 | 0.3% | Jul 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of ... |
| CVE-2026-9770 | MEDIUM | 5.3 | 0.3% | Jul 15, 2026 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s... |
| CVE-2026-13230 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan... |
| CVE-2026-5270 | CRITICAL | 9.8 | 0.2% | Jul 14, 2026 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage... |
| CVE-2026-5269 | CRITICAL | 9.8 | 0.1% | Jul 14, 2026 | In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used fo... |
| CVE-2026-51808 | CRITICAL | 9.8 | 0.2% | Jul 14, 2026 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the open... |
| CVE-2026-51807 | CRITICAL | 9.8 | 0.5% | Jul 14, 2026 | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (... |
| CVE-2026-36035 | MEDIUM | 6.5 | 0.2% | Jul 14, 2026 | Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser... |
| CVE-2026-15753 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown ... |
| CVE-2026-15752 | HIGH | 7.3 | — | Jul 14, 2026 | A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a... |
| CVE-2026-15751 | MEDIUM | 5.3 | 0.1% | Jul 14, 2026 | A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th... |
