CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58705
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue …

Jun 2, 2026
CVE-2025-58024
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion. This …

Jun 2, 2026
CVE-2025-53440
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. This issue …

Jun 2, 2026
CVE-2026-5422
8.1 HIGH

A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check …

Jun 2, 2026
CVE-2025-53345
8.8 HIGH

Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3.

Jun 2, 2026
CVE-2025-52759
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a …

Jun 2, 2026
CVE-2026-3514
7.5 HIGH

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the …

Jun 2, 2026
CVE-2026-1784
8.8 HIGH

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on …

Jun 2, 2026
CVE-2026-8293
7.5 HIGH

The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker …

Jun 2, 2026
CVE-2026-25277
8.8 HIGH

Memory corruption while using Strongbox due to buffer overflow.

Jun 1, 2026
CVE-2026-25276
8.8 HIGH

Memory corruption while using Strongbox due to missing bounds check.

Jun 1, 2026
CVE-2026-25260
7.8 HIGH

Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.

Jun 1, 2026
CVE-2026-25259
7.8 HIGH

Memory corruption while processing multiple IOCTL command for escape operations.

Jun 1, 2026
CVE-2026-25258
7.8 HIGH

Memory corruption while processing IOCTL calls for escape operations.

Jun 1, 2026
CVE-2026-24782
7.6 HIGH

Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated …

Jun 1, 2026
CVE-2026-24752
8.2 HIGH

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker …

Jun 1, 2026
CVE-2026-24092
7.2 HIGH

Memory Corruption when processing fastboot commands to set display mode.

Jun 1, 2026
CVE-2026-24091
7.2 HIGH

Memory corruption while processing fastboot commands with improperly formatted input.

Jun 1, 2026
CVE-2026-24090
7.1 HIGH

Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.

Jun 1, 2026
CVE-2026-24089
7.2 HIGH

Memory corruption while processing fastboot commands with invalid input.

Jun 1, 2026
CVE-2026-24088
8.2 HIGH

Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.

Jun 1, 2026
CVE-2026-24087
7.2 HIGH

Memory corruption while processing fastboot OEM commands.

Jun 1, 2026
CVE-2026-24085
7.2 HIGH

Memory Corruption when processing display command line information due to improper initialization of a variable.

Jun 1, 2026
CVE-2025-59606
7.8 HIGH

Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.

Jun 1, 2026
CVE-2025-59605
7.8 HIGH

Memory Corruption when processing device identifier strings that exceed the expected maximum length.

Jun 1, 2026
CVE-2025-59604
7.8 HIGH

Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.

Jun 1, 2026
CVE-2019-25718
8.4 HIGH

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through …

Jun 1, 2026
CVE-2026-49491
8.2 HIGH

Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers …

Jun 1, 2026
CVE-2026-40964
7.5 HIGH

Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for …

Jun 1, 2026
CVE-2026-28580
7.8 HIGH

In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with …

Jun 1, 2026
CVE-2026-28577
7.8 HIGH

In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no …

Jun 1, 2026
CVE-2026-10293
8.8 HIGH

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formFireWall. This manipulation of the …

Jun 1, 2026
CVE-2026-10292
8.8 HIGH

A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based …

Jun 1, 2026
CVE-2026-10290
7.3 HIGH

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of …

Jun 1, 2026
CVE-2026-0100
7.8 HIGH

In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Jun 1, 2026
CVE-2026-0099
7.8 HIGH

In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This …

Jun 1, 2026
CVE-2026-0098
7.8 HIGH

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation …

Jun 1, 2026
CVE-2026-0097
8.0 HIGH

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead …

Jun 1, 2026
CVE-2026-0096
7.8 HIGH

In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to …

Jun 1, 2026
CVE-2026-0095
8.0 HIGH

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This …

Jun 1, 2026
CVE-2026-0094
7.8 HIGH

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This …

Jun 1, 2026
CVE-2026-0093
7.8 HIGH

In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges …

Jun 1, 2026
CVE-2026-0091
7.8 HIGH

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to …

Jun 1, 2026
CVE-2026-0089
7.8 HIGH

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local …

Jun 1, 2026
CVE-2026-0088
7.8 HIGH

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to …

Jun 1, 2026
CVE-2026-0087
7.8 HIGH

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could …

Jun 1, 2026
CVE-2026-0078
7.8 HIGH

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with …

Jun 1, 2026
CVE-2026-0077
7.8 HIGH

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local …

Jun 1, 2026
CVE-2026-0076
7.8 HIGH

In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of …

Jun 1, 2026
CVE-2026-0059
8.0 HIGH

In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote …

Jun 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.