CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50891
8.1 HIGH

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

Jun 15, 2026
CVE-2026-50890
9.8 CRITICAL

Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive …

Jun 15, 2026
CVE-2026-50889
7.5 HIGH

An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a …

Jun 15, 2026
CVE-2026-50888
8.1 HIGH

An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying …

Jun 15, 2026
CVE-2026-50887
9.1 CRITICAL

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a …

Jun 15, 2026
CVE-2026-50886
9.1 CRITICAL

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.

Jun 15, 2026
CVE-2026-50885
7.5 HIGH

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.

Jun 15, 2026
CVE-2026-50884
8.8 HIGH

Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.

Jun 15, 2026
CVE-2026-50883
9.6 CRITICAL

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.

Jun 15, 2026
CVE-2026-50882
7.5 HIGH

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

Jun 15, 2026
CVE-2026-50881
8.1 HIGH

Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and …

Jun 15, 2026
CVE-2026-50880
9.8 CRITICAL

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.

Jun 15, 2026
CVE-2026-50879
7.5 HIGH

An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

Jun 15, 2026
CVE-2026-50878
7.5 HIGH

An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.

Jun 15, 2026
CVE-2026-50877
7.5 HIGH

An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.

Jun 15, 2026
CVE-2026-50876
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Jun 15, 2026
CVE-2026-50875
8.1 HIGH

Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted …

Jun 15, 2026
CVE-2026-50874
8.1 HIGH

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

Jun 15, 2026
CVE-2026-50873
9.8 CRITICAL

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or …

Jun 15, 2026
CVE-2026-50872
9.8 CRITICAL

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a …

Jun 15, 2026
CVE-2026-50871
9.8 CRITICAL

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying …

Jun 15, 2026
CVE-2026-50870
7.5 HIGH

An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive information via a crafted GET request.

Jun 15, 2026
CVE-2026-50869
9.8 CRITICAL

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

Jun 15, 2026
CVE-2026-49954
7.2 HIGH

Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted …

Jun 15, 2026
CVE-2026-49953
6.5 MEDIUM

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and …

Jun 15, 2026
CVE-2026-49952
9.1 CRITICAL

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore …

Jun 15, 2026
CVE-2026-48114
9.8 CRITICAL

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the …

Jun 15, 2026
CVE-2026-47835
8.6 HIGH

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: …

Jun 15, 2026
CVE-2026-45390
9.1 CRITICAL

In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, …

Jun 15, 2026
CVE-2026-45389
7.4 HIGH

In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with …

Jun 15, 2026
CVE-2026-45388
9.1 CRITICAL

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not …

Jun 15, 2026
CVE-2026-41708
7.5 HIGH

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is …

Jun 15, 2026
CVE-2026-39197
6.5 MEDIUM

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or …

Jun 15, 2026
CVE-2026-39196
9.8 CRITICAL

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to …

Jun 15, 2026
CVE-2026-39118
8.4 HIGH

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent …

Jun 15, 2026
CVE-2026-39007
7.5 HIGH

An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.

Jun 15, 2026
CVE-2026-39006
9.8 CRITICAL

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

Jun 15, 2026
CVE-2026-38812
9.8 CRITICAL

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with …

Jun 15, 2026
CVE-2026-38329
9.8 CRITICAL

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks …

Jun 15, 2026
CVE-2026-38065
9.8 CRITICAL

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

Jun 15, 2026
CVE-2026-38064
9.8 CRITICAL

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.

Jun 15, 2026
CVE-2026-38063
9.8 CRITICAL

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.

Jun 15, 2026
CVE-2026-38062
9.8 CRITICAL

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.

Jun 15, 2026
CVE-2026-38061
9.8 CRITICAL

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

Jun 15, 2026
CVE-2026-38060
9.8 CRITICAL

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.

Jun 15, 2026
CVE-2026-37216
6.1 MEDIUM

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

Jun 15, 2026
CVE-2026-36933
6.8 MEDIUM

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

Jun 15, 2026
CVE-2026-36670
8.8 HIGH

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary …

Jun 15, 2026
CVE-2026-36537
9.8 CRITICAL

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter …

Jun 15, 2026
CVE-2026-36521
6.1 MEDIUM

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.