CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2019-25732
8.2 HIGH

PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search …

Jun 4, 2026
CVE-2019-25731
6.1 MEDIUM

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can …

Jun 4, 2026
CVE-2019-25730
8.2 HIGH

Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id …

Jun 4, 2026
CVE-2019-25729
9.8 CRITICAL

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie …

Jun 4, 2026
CVE-2019-25728
8.2 HIGH

Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject …

Jun 4, 2026
CVE-2019-25727
9.8 CRITICAL

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. …

Jun 4, 2026
CVE-2019-25726
8.2 HIGH

All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through …

Jun 4, 2026
CVE-2026-4104
9.8 CRITICAL

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: …

Jun 4, 2026
CVE-2026-45432

This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A …

Jun 4, 2026
CVE-2026-45431

This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An …

Jun 4, 2026
CVE-2026-10843
7.2 HIGH

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions …

Jun 4, 2026
CVE-2026-10840
7.1 HIGH

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via …

Jun 4, 2026
CVE-2026-10804
3.6 LOW

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such …

Jun 4, 2026
CVE-2026-10803
3.6 LOW

A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest …

Jun 4, 2026
CVE-2026-10802
4.3 MEDIUM

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. …

Jun 4, 2026
CVE-2025-52612
7.1 HIGH

HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an …

Jun 4, 2026
CVE-2025-52611
3.1 LOW

HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the …

Jun 4, 2026
CVE-2025-52609
3.7 LOW

HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern …

Jun 4, 2026
CVE-2025-52608
3.1 LOW

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. …

Jun 4, 2026
CVE-2025-52606
4.3 MEDIUM

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected …

Jun 4, 2026
CVE-2025-12694

A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN …

Jun 4, 2026
CVE-2026-49077
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue …

Jun 4, 2026
CVE-2026-10801
3.6 LOW

A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL …

Jun 4, 2026
CVE-2026-8916
6.1 MEDIUM

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.

Jun 4, 2026
CVE-2026-50226
5.3 MEDIUM

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items …

Jun 4, 2026
CVE-2026-50225
9.1 CRITICAL

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Jun 4, 2026
CVE-2026-50224
4.9 MEDIUM

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over …

Jun 4, 2026
CVE-2026-50214
9.8 CRITICAL

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

Jun 4, 2026
CVE-2026-4881

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a …

Jun 4, 2026
CVE-2026-49771
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue …

Jun 4, 2026
CVE-2026-49510
6.1 MEDIUM

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.

Jun 4, 2026
CVE-2026-47320
6.1 MEDIUM

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Jun 4, 2026
CVE-2026-47319
6.1 MEDIUM

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

Jun 4, 2026
CVE-2026-47318
6.1 MEDIUM

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.

Jun 4, 2026
CVE-2026-47306
6.1 MEDIUM

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.

Jun 4, 2026
CVE-2026-10800
3.6 LOW

A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the …

Jun 4, 2026
CVE-2026-10305
6.1 MEDIUM

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Jun 4, 2026
CVE-2026-50213
7.5 HIGH

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

Jun 4, 2026
CVE-2026-50212
6.5 MEDIUM

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

Jun 4, 2026
CVE-2026-50211
9.8 CRITICAL

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

Jun 4, 2026
CVE-2026-50210
7.5 HIGH

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.

Jun 4, 2026
CVE-2026-50209
7.8 HIGH

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.

Jun 4, 2026
CVE-2026-50208
9.4 CRITICAL

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

Jun 4, 2026
CVE-2026-50207
7.8 HIGH

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.

Jun 4, 2026
CVE-2026-3820
7.2 HIGH

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain administrator privileges and inject specially crafted characters into …

Jun 4, 2026
CVE-2026-50206
6.8 MEDIUM

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Jun 4, 2026
CVE-2026-50205
8.2 HIGH

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

Jun 4, 2026
CVE-2026-49204
6.5 MEDIUM

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Jun 4, 2026
CVE-2026-49203
8.3 HIGH

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

Jun 4, 2026
CVE-2026-49202
8.6 HIGH

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.

Jun 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.