CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-35262
8.3 HIGH

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable …

Jun 17, 2026
CVE-2026-35261
6.5 MEDIUM

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable …

Jun 17, 2026
CVE-2026-35259
8.8 HIGH

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows …

Jun 17, 2026
CVE-2026-35258
8.7 HIGH

Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows …

Jun 17, 2026
CVE-2026-12348
7.4 HIGH

Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, …

Jun 17, 2026
CVE-2026-48777

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in …

Jun 16, 2026
CVE-2026-47750
7.8 HIGH

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, …

Jun 16, 2026
CVE-2026-47747
7.8 HIGH

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, …

Jun 16, 2026
CVE-2026-46448
5.4 MEDIUM

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

Jun 16, 2026
CVE-2026-22313
9.1 CRITICAL

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability …

Jun 16, 2026
CVE-2026-22312
8.6 HIGH

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to …

Jun 16, 2026
CVE-2026-12425

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects …

Jun 16, 2026
CVE-2026-12117
4.3 MEDIUM

Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to …

Jun 16, 2026
CVE-2026-12105
6.5 MEDIUM

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.

Jun 16, 2026
CVE-2026-11890
4.3 MEDIUM

Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.

Jun 16, 2026
CVE-2026-10303
7.4 HIGH

In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used …

Jun 16, 2026
CVE-2026-0165
5.7 MEDIUM

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote …

Jun 16, 2026
CVE-2026-0164
8.8 HIGH

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no …

Jun 16, 2026
CVE-2026-0162
8.8 HIGH

In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no additional execution …

Jun 16, 2026
CVE-2026-0161
8.8 HIGH

In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege …

Jun 16, 2026
CVE-2026-0160
8.8 HIGH

In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jun 16, 2026
CVE-2026-0158
3.3 LOW

In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with …

Jun 16, 2026
CVE-2026-0157
4.3 MEDIUM

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution …

Jun 16, 2026
CVE-2026-0156

In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service …

Jun 16, 2026
CVE-2026-0155
4.3 MEDIUM

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution …

Jun 16, 2026
CVE-2026-0154
8.8 HIGH

In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to …

Jun 16, 2026
CVE-2026-0153
7.8 HIGH

In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jun 16, 2026
CVE-2026-0152
7.8 HIGH

In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of bounds …

Jun 16, 2026
CVE-2026-0151
8.8 HIGH

In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with …

Jun 16, 2026
CVE-2026-0150
7.8 HIGH

In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to local …

Jun 16, 2026
CVE-2026-0149
8.8 HIGH

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution …

Jun 16, 2026
CVE-2026-0148
8.8 HIGH

In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution …

Jun 16, 2026
CVE-2026-0147
8.8 HIGH

In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jun 16, 2026
CVE-2026-0146
8.8 HIGH

In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jun 16, 2026
CVE-2026-0145
3.3 LOW

In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no …

Jun 16, 2026
CVE-2026-0144
6.5 MEDIUM

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service …

Jun 16, 2026
CVE-2026-0143
7.8 HIGH

In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with …

Jun 16, 2026
CVE-2026-0142
3.3 LOW

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with …

Jun 16, 2026
CVE-2026-0141
4.3 MEDIUM

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no …

Jun 16, 2026
CVE-2026-0140
4.3 MEDIUM

In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges …

Jun 16, 2026
CVE-2026-0139
8.8 HIGH

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no …

Jun 16, 2026
CVE-2026-0138
7.8 HIGH

In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with …

Jun 16, 2026
CVE-2026-0137
7.8 HIGH

In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege …

Jun 16, 2026
CVE-2026-0136
6.5 MEDIUM

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Jun 16, 2026
CVE-2026-0135
7.8 HIGH

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no …

Jun 16, 2026
CVE-2026-0134
3.3 LOW

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could …

Jun 16, 2026
CVE-2026-0133
7.8 HIGH

In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead …

Jun 16, 2026
CVE-2026-0132
8.8 HIGH

In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no …

Jun 16, 2026
CVE-2026-0131
7.3 HIGH

In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no …

Jun 16, 2026
CVE-2026-0130
3.5 LOW

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no …

Jun 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.