CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-57943
5.9 MEDIUM

LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' …

Jun 29, 2026
CVE-2026-57942
5.3 MEDIUM

LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses …

Jun 29, 2026
CVE-2026-56783
6.5 MEDIUM

Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basic-auth credentials in cleartext due to commented-out …

Jun 29, 2026
CVE-2026-56781
5.3 MEDIUM

Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the …

Jun 29, 2026
CVE-2026-13752
6.0 MEDIUM

Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to …

Jun 29, 2026
CVE-2026-13751
4.1 MEDIUM

Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference …

Jun 29, 2026
CVE-2026-13591
5.0 MEDIUM

A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of the component Contact Tracking. This manipulation …

Jun 29, 2026
CVE-2026-13590
5.6 MEDIUM

A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/header/ModbusLayer.h of the component Modbus Protocol Handler. …

Jun 29, 2026
CVE-2026-13589
5.6 MEDIUM

A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand of the file Packet++/src/TelnetLayer.cpp of the component Telnet Subnegotiation Packet Handler. The …

Jun 29, 2026
CVE-2026-13588
5.6 MEDIUM

A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMessage::getHandshakeVersion of the file Packet++/src/SSLHandshake.cpp of the component TLS Hello Handler. …

Jun 29, 2026
CVE-2026-9105
6.5 MEDIUM

An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests …

Jun 29, 2026
CVE-2026-13750
5.5 MEDIUM

Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. …

Jun 29, 2026
CVE-2026-13748
6.3 MEDIUM

Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake …

Jun 29, 2026
CVE-2026-13581
6.3 MEDIUM

A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The …

Jun 29, 2026
CVE-2026-13437
6.5 MEDIUM

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent …

Jun 29, 2026
CVE-2026-57341
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.

Jun 29, 2026
CVE-2026-57340
6.5 MEDIUM

Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

Jun 29, 2026
CVE-2026-57339
6.5 MEDIUM

Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

Jun 29, 2026
CVE-2026-57335
6.5 MEDIUM

Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

Jun 29, 2026
CVE-2026-57334
6.5 MEDIUM

Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

Jun 29, 2026
CVE-2026-57330
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.

Jun 29, 2026
CVE-2026-57329
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.

Jun 29, 2026
CVE-2026-57328
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

Jun 29, 2026
CVE-2026-57327
6.3 MEDIUM

Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

Jun 29, 2026
CVE-2026-57326
6.1 MEDIUM

Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

Jun 29, 2026
CVE-2026-46406
6.1 MEDIUM

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without …

Jun 29, 2026
CVE-2026-13579
6.3 MEDIUM

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a …

Jun 29, 2026
CVE-2026-13578
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing …

Jun 29, 2026
CVE-2026-13572
6.3 MEDIUM

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation of …

Jun 29, 2026
CVE-2026-13571
5.3 MEDIUM

A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a …

Jun 29, 2026
CVE-2026-56457
4.3 MEDIUM

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with …

Jun 29, 2026
CVE-2026-54370
6.3 MEDIUM

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component …

Jun 29, 2026
CVE-2026-13569
4.7 MEDIUM

A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processing of the file /index.php of the component …

Jun 29, 2026
CVE-2026-13567
4.3 MEDIUM

A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST …

Jun 29, 2026
CVE-2026-41991
4.7 MEDIUM

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s …

Jun 29, 2026
CVE-2026-13561
6.3 MEDIUM

A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. …

Jun 29, 2026
CVE-2026-13560
6.3 MEDIUM

A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST …

Jun 29, 2026
CVE-2026-13557
4.3 MEDIUM

A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request …

Jun 29, 2026
CVE-2026-13556
4.3 MEDIUM

A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request …

Jun 29, 2026
CVE-2026-13554
4.3 MEDIUM

A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of …

Jun 29, 2026
CVE-2026-57966
4.4 MEDIUM

A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on …

Jun 29, 2026
CVE-2026-57965
5.1 MEDIUM

A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability …

Jun 29, 2026
CVE-2026-57676
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User …

Jun 29, 2026
CVE-2026-13595
6.8 MEDIUM

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a …

Jun 29, 2026
CVE-2026-13549
5.4 MEDIUM

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the …

Jun 29, 2026
CVE-2026-13548
6.3 MEDIUM

A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument editid …

Jun 29, 2026
CVE-2026-9676
4.3 MEDIUM

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users …

Jun 29, 2026
CVE-2026-13544
6.3 MEDIUM

A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the …

Jun 29, 2026
CVE-2026-13543
5.6 MEDIUM

A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts of the component Google …

Jun 29, 2026
CVE-2026-13542
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the …

Jun 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.