CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-57436
5.3 MEDIUM

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was …

Jun 25, 2026
CVE-2026-49319
6.5 MEDIUM

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a …

Jun 25, 2026
CVE-2026-57619
6.5 MEDIUM

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

Jun 25, 2026
CVE-2026-57429
6.5 MEDIUM

Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

Jun 25, 2026
CVE-2026-56050
6.5 MEDIUM

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a …

Jun 25, 2026
CVE-2026-56023
5.4 MEDIUM

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

Jun 25, 2026
CVE-2026-56013
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

Jun 25, 2026
CVE-2026-52690
5.9 MEDIUM

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server …

Jun 25, 2026
CVE-2026-4526
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come …

Jun 25, 2026
CVE-2026-47154
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come …

Jun 25, 2026
CVE-2026-47153
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a …

Jun 25, 2026
CVE-2026-47152
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a …

Jun 25, 2026
CVE-2026-47149
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come …

Jun 25, 2026
CVE-2026-47148
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages …

Jun 25, 2026
CVE-2026-47146
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that …

Jun 25, 2026
CVE-2026-47145
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that …

Jun 25, 2026
CVE-2026-46732
6.7 MEDIUM

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A …

Jun 25, 2026
CVE-2026-42390
5.3 MEDIUM

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

Jun 25, 2026
CVE-2026-42389
5.3 MEDIUM

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

Jun 25, 2026
CVE-2026-42388
5.9 MEDIUM

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

Jun 25, 2026
CVE-2026-42387
5.9 MEDIUM

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input …

Jun 25, 2026
CVE-2026-40012
5.3 MEDIUM

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

Jun 25, 2026
CVE-2026-40211
5.3 MEDIUM

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be …

Jun 25, 2026
CVE-2026-40210
4.8 MEDIUM

An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.

Jun 25, 2026
CVE-2026-40209
5.3 MEDIUM

An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by …

Jun 25, 2026
CVE-2026-42005
4.3 MEDIUM

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal …

Jun 25, 2026
CVE-2026-53196
6.8 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device …

Jun 25, 2026
CVE-2026-56129
5.5 MEDIUM

Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user …

Jun 25, 2026
CVE-2026-10824
6.5 MEDIUM

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently …

Jun 25, 2026
CVE-2026-8330
4.4 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-5952
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-5796
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-5309
5.4 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-2238
5.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-1606
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain …

Jun 25, 2026
CVE-2026-11379
5.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 …

Jun 25, 2026
CVE-2026-2508
6.5 MEDIUM

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 …

Jun 25, 2026
CVE-2026-12079
6.5 MEDIUM

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due …

Jun 25, 2026
CVE-2026-10833
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block …

Jun 25, 2026
CVE-2026-8658
6.0 MEDIUM

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters …

Jun 25, 2026
CVE-2026-8664
6.0 MEDIUM

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters …

Jun 25, 2026
CVE-2026-9153
6.5 MEDIUM

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient …

Jun 25, 2026
CVE-2026-8663
6.0 MEDIUM

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name …

Jun 25, 2026
CVE-2026-8659
6.0 MEDIUM

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters …

Jun 25, 2026
CVE-2025-60473
5.5 MEDIUM

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Jun 25, 2026
CVE-2025-60466
5.0 MEDIUM

A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 25, 2026
CVE-2026-39900
6.1 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php …

Jun 24, 2026
CVE-2026-39899
5.3 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This …

Jun 24, 2026
CVE-2026-9775
6.5 MEDIUM

ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication …

Jun 24, 2026
CVE-2026-9774
6.5 MEDIUM

ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication …

Jun 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.