CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-46304
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the …

Jun 8, 2026
CVE-2026-46303
8.2 HIGH

In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from …

Jun 8, 2026
CVE-2026-46299
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super() hfsplus_fill_super() calls hfs_find_init() to initialize a search structure, …

Jun 8, 2026
CVE-2026-46288
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_changeset() The variable 'parent' is assigned the value of 'nchangeset' …

Jun 8, 2026
CVE-2026-46280
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: lib: test_hmm: evict device pages on file close to avoid use-after-free Patch series "Minor hmm_test …

Jun 8, 2026
CVE-2026-46277
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after calling ->folio_free() The contents of a device folio …

Jun 8, 2026
CVE-2026-25856
8.8 HIGH

OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by …

Jun 8, 2026
CVE-2026-25855
8.8 HIGH

OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by uploading script files (.bat.ps1.sh) through the …

Jun 8, 2026
CVE-2026-25559
8.8 HIGH

OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete …

Jun 8, 2026
CVE-2026-11531
7.3 HIGH

A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator …

Jun 8, 2026
CVE-2026-11530
7.3 HIGH

A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation …

Jun 8, 2026
CVE-2026-49975
7.5 HIGH

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache …

Jun 8, 2026
CVE-2026-48913
7.3 HIGH

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through …

Jun 8, 2026
CVE-2026-46657
7.1 HIGH

Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access …

Jun 8, 2026
CVE-2026-46656
8.8 HIGH

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding …

Jun 8, 2026
CVE-2026-46480
8.8 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment …

Jun 8, 2026
CVE-2026-46475
8.8 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment …

Jun 8, 2026
CVE-2026-46444
8.8 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI …

Jun 8, 2026
CVE-2026-46275
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to …

Jun 8, 2026
CVE-2026-46274
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_wq_remove_pending() io_wq_remove_pending() needs to fix up wq->hash_tail[] …

Jun 8, 2026
CVE-2026-44186
7.3 HIGH

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue …

Jun 8, 2026
CVE-2026-44185
7.3 HIGH

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 …

Jun 8, 2026
CVE-2026-42863
8.1 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists …

Jun 8, 2026
CVE-2026-42536
7.5 HIGH

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users …

Jun 8, 2026
CVE-2026-36786
7.5 HIGH

Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 parameter of the fromDhcpListClient function. This vulnerability …

Jun 8, 2026
CVE-2026-34356
7.5 HIGH

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users …

Jun 8, 2026
CVE-2026-34355
7.5 HIGH

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to …

Jun 8, 2026
CVE-2026-34194
7.1 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse …

Jun 8, 2026
CVE-2026-22164
7.5 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. By creating resources of certain types …

Jun 8, 2026
CVE-2026-11528
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. …

Jun 8, 2026
CVE-2026-11524
8.8 HIGH

A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The …

Jun 8, 2026
CVE-2026-11523
8.8 HIGH

A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. …

Jun 8, 2026
CVE-2026-11522
8.8 HIGH

A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts …

Jun 8, 2026
CVE-2026-49235
7.5 HIGH

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

Jun 8, 2026
CVE-2026-49234
7.5 HIGH

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access …

Jun 8, 2026
CVE-2026-49233
7.5 HIGH

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This …

Jun 8, 2026
CVE-2026-36789
7.5 HIGH

Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. …

Jun 8, 2026
CVE-2026-11517
8.8 HIGH

A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of the …

Jun 8, 2026
CVE-2026-11577
7.2 HIGH

A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to …

Jun 8, 2026
CVE-2026-50752
7.4 HIGH

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate …

Jun 8, 2026
CVE-2026-11504
8.8 HIGH

A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration …

Jun 8, 2026
CVE-2026-11503
8.8 HIGH

A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set of the component Wi-Fi …

Jun 8, 2026
CVE-2026-11501
7.3 HIGH

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=save_patient. The …

Jun 8, 2026
CVE-2026-41724
8.0 HIGH

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject …

Jun 8, 2026
CVE-2026-41723
8.0 HIGH

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject …

Jun 8, 2026
CVE-2026-41722
8.0 HIGH

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject …

Jun 8, 2026
CVE-2026-3238
7.5 HIGH

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types …

Jun 8, 2026
CVE-2026-11498
8.8 HIGH

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component …

Jun 8, 2026
CVE-2026-11490
7.3 HIGH

A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument …

Jun 8, 2026
CVE-2026-11489
7.3 HIGH

A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID …

Jun 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.