CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-36501
7.5 HIGH

An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Jun 5, 2026
CVE-2026-11344
7.3 HIGH

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration …

Jun 5, 2026
CVE-2026-11342
7.3 HIGH

A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of …

Jun 5, 2026
CVE-2025-5088
8.3 HIGH

An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an …

Jun 5, 2026
CVE-2026-48095
8.8 HIGH

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in …

Jun 5, 2026
CVE-2026-11334
7.3 HIGH

A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file dashboard_page/forms/fetch.php. Performing a manipulation of the argument department_code results …

Jun 5, 2026
CVE-2026-50234
7.5 HIGH

Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server …

Jun 5, 2026
CVE-2026-50232
7.2 HIGH

Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file metadata tags like GENRE, ARTIST, …

Jun 5, 2026
CVE-2026-50231
7.2 HIGH

Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject malicious scripts by exploiting unescaped …

Jun 5, 2026
CVE-2026-50264
7.8 HIGH

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft …

Jun 5, 2026
CVE-2026-50261
7.8 HIGH

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free …

Jun 5, 2026
CVE-2026-50260
7.8 HIGH

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those …

Jun 5, 2026
CVE-2026-50259
7.8 HIGH

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type …

Jun 5, 2026
CVE-2026-50258
7.8 HIGH

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups …

Jun 5, 2026
CVE-2026-50257
7.8 HIGH

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a …

Jun 5, 2026
CVE-2026-50256
7.8 HIGH

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum …

Jun 5, 2026
CVE-2026-21033
7.1 HIGH

Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

Jun 5, 2026
CVE-2026-21032
7.1 HIGH

Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

Jun 5, 2026
CVE-2026-21031
7.8 HIGH

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

Jun 5, 2026
CVE-2026-21030
7.8 HIGH

Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

Jun 5, 2026
CVE-2026-21029
7.8 HIGH

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

Jun 5, 2026
CVE-2026-11332
7.8 HIGH

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument …

Jun 5, 2026
CVE-2026-21837
8.8 HIGH

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, …

Jun 5, 2026
CVE-2026-50593
7.3 HIGH

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the …

Jun 5, 2026
CVE-2026-41567
7.2 HIGH

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded …

Jun 5, 2026
CVE-2026-11307
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jun 5, 2026
CVE-2026-11306
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jun 5, 2026
CVE-2026-11305
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jun 5, 2026
CVE-2026-11304
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 5, 2026
CVE-2026-11303
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jun 5, 2026
CVE-2026-11301
8.8 HIGH

Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network …

Jun 5, 2026
CVE-2026-11297
7.7 HIGH

Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to bypass navigation restrictions via …

Jun 5, 2026
CVE-2026-11296
7.5 HIGH

Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via …

Jun 5, 2026
CVE-2026-11295
8.8 HIGH

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. …

Jun 5, 2026
CVE-2026-11279
8.8 HIGH

Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

Jun 5, 2026
CVE-2026-11272
8.8 HIGH

Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to …

Jun 5, 2026
CVE-2026-11269
7.1 HIGH

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox …

Jun 5, 2026
CVE-2026-11265
7.5 HIGH

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jun 5, 2026
CVE-2026-11262
8.8 HIGH

Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium …

Jun 5, 2026
CVE-2026-11256
8.3 HIGH

Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jun 5, 2026
CVE-2026-11255
7.5 HIGH

Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process …

Jun 5, 2026
CVE-2026-11248
8.8 HIGH

Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium …

Jun 5, 2026
CVE-2026-11242
7.5 HIGH

Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak …

Jun 5, 2026
CVE-2026-11241
8.0 HIGH

Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation …

Jun 5, 2026
CVE-2026-11239
7.5 HIGH

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via …

Jun 5, 2026
CVE-2026-10877
7.3 HIGH

A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of the file /admin/login.php …

Jun 5, 2026
CVE-2026-10586
7.2 HIGH

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Jun 5, 2026
CVE-2026-45497
7.7 HIGH

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

Jun 4, 2026
CVE-2026-20245
7.8 HIGH KEV

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, …

Jun 4, 2026
CVE-2026-11237
8.3 HIGH

Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform …

Jun 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.