CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-36213
7.8 HIGH

An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

Jun 15, 2026
CVE-2026-30121
9.1 CRITICAL

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

Jun 15, 2026
CVE-2026-30120
9.8 CRITICAL

remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.

Jun 15, 2026
CVE-2026-11931
5.5 MEDIUM

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or …

Jun 15, 2026
CVE-2025-70102
6.3 MEDIUM

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a …

Jun 15, 2026
CVE-2025-68713
8.0 HIGH

An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary …

Jun 15, 2026
CVE-2025-56814
7.8 HIGH

A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.

Jun 15, 2026
CVE-2025-55663
5.5 MEDIUM

A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55661
5.5 MEDIUM

A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via …

Jun 15, 2026
CVE-2025-55660
5.5 MEDIUM

A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55652
5.5 MEDIUM

A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55650
5.5 MEDIUM

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55649
5.5 MEDIUM

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55648
5.5 MEDIUM

A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55647
5.5 MEDIUM

An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 …

Jun 15, 2026
CVE-2025-55645
5.5 MEDIUM

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55644
5.5 MEDIUM

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55643
5.5 MEDIUM

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying …

Jun 15, 2026
CVE-2025-55642
6.5 MEDIUM

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).

Jun 15, 2026
CVE-2025-55641
5.5 MEDIUM

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2026-8358

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two …

Jun 15, 2026
CVE-2026-8357

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening …

Jun 15, 2026
CVE-2026-8356

LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were …

Jun 15, 2026
CVE-2026-6047

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A …

Jun 15, 2026
CVE-2026-6045

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of …

Jun 15, 2026
CVE-2026-6040

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against …

Jun 15, 2026
CVE-2026-6039

LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count …

Jun 15, 2026
CVE-2026-49294
6.1 MEDIUM

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to reflected cross-site scripting …

Jun 15, 2026
CVE-2026-47777
7.5 HIGH

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented …

Jun 15, 2026
CVE-2026-20262
6.5 MEDIUM KEV

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or …

Jun 15, 2026
CVE-2026-9863
7.5 HIGH

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised …

Jun 15, 2026
CVE-2026-9862
9.8 CRITICAL

Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service …

Jun 15, 2026
CVE-2026-9595
5.3 MEDIUM

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket …

Jun 15, 2026
CVE-2026-8683
6.5 MEDIUM

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious …

Jun 15, 2026
CVE-2026-5038
5.3 MEDIUM

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned …

Jun 15, 2026
CVE-2026-10634
4.8 MEDIUM

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. …

Jun 15, 2026
CVE-2025-15659
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

Jun 15, 2026
CVE-2025-15658
5.9 MEDIUM

Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.

Jun 15, 2026
CVE-2026-6517
6.3 MEDIUM

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop …

Jun 15, 2026
CVE-2026-5242
8.8 HIGH

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from …

Jun 15, 2026
CVE-2026-5233
7.1 HIGH

Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Jun 15, 2026
CVE-2026-5230
7.1 HIGH

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: …

Jun 15, 2026
CVE-2026-5079
7.5 HIGH

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The …

Jun 15, 2026
CVE-2026-52704
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF …

Jun 15, 2026
CVE-2026-49111
8.8 HIGH

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

Jun 15, 2026
CVE-2026-49064
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

Jun 15, 2026
CVE-2026-49062
8.8 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

Jun 15, 2026
CVE-2026-48969
6.5 MEDIUM

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

Jun 15, 2026
CVE-2025-64215
6.5 MEDIUM

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before …

Jun 15, 2026
CVE-2019-25746
7.1 HIGH

WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' …

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.