CVE Database

135497+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-8720
7.5 HIGH

wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the …

Jun 25, 2026
CVE-2026-7532
7.5 HIGH

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an …

Jun 25, 2026
CVE-2026-7511
7.5 HIGH

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.

Jun 25, 2026
CVE-2026-6331
7.5 HIGH

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the …

Jun 25, 2026
CVE-2026-6330
6.5 MEDIUM

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code …

Jun 25, 2026
CVE-2026-6329
6.5 MEDIUM

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 …

Jun 25, 2026
CVE-2026-6325
7.5 HIGH

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.

Jun 25, 2026
CVE-2026-6092
5.3 MEDIUM

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

Jun 25, 2026
CVE-2026-55962
6.5 MEDIUM

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The …

Jun 25, 2026
CVE-2026-54479
7.3 HIGH

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results …

Jun 25, 2026
CVE-2026-50176
7.5 HIGH

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service …

Jun 25, 2026
CVE-2026-44622
6.5 MEDIUM

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Jun 25, 2026
CVE-2026-40702
9.4 CRITICAL

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to …

Jun 25, 2026
CVE-2026-22879
8.1 HIGH

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

Jun 25, 2026
CVE-2026-13283
7.5 HIGH

Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific …

Jun 25, 2026
CVE-2026-13282
6.8 MEDIUM

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access …

Jun 25, 2026
CVE-2026-13281
8.3 HIGH

Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jun 25, 2026
CVE-2026-12992
7.4 HIGH

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to …

Jun 25, 2026
CVE-2026-12975
8.5 HIGH

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker …

Jun 25, 2026
CVE-2026-11800
8.1 HIGH

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to …

Jun 25, 2026
CVE-2026-11703
7.5 HIGH

Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a …

Jun 25, 2026
CVE-2026-10098
5.3 MEDIUM

OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation …

Jun 25, 2026
CVE-2025-71340
8.1 HIGH

picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes …

Jun 25, 2026
CVE-2025-71338
10.0 CRITICAL

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized …

Jun 25, 2026
CVE-2025-71336
9.8 CRITICAL

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute …

Jun 25, 2026
CVE-2025-71335
8.1 HIGH

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who …

Jun 25, 2026
CVE-2025-71334
9.8 CRITICAL

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are …

Jun 25, 2026
CVE-2025-71333
9.8 CRITICAL

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal …

Jun 25, 2026
CVE-2025-71328
8.3 HIGH

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying …

Jun 25, 2026
CVE-2025-71327
9.1 CRITICAL

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint …

Jun 25, 2026
CVE-2025-71324
7.5 HIGH

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated …

Jun 25, 2026
CVE-2021-47987
7.5 HIGH

Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an …

Jun 25, 2026
CVE-2021-47986
7.5 HIGH

Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal …

Jun 25, 2026
CVE-2020-37256
5.4 MEDIUM

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject …

Jun 25, 2026
CVE-2026-6731
7.5 HIGH

X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS …

Jun 25, 2026
CVE-2026-6681
5.3 MEDIUM

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This …

Jun 25, 2026
CVE-2026-6679
7.5 HIGH

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to …

Jun 25, 2026
CVE-2026-6678
5.3 MEDIUM

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

Jun 25, 2026
CVE-2026-6450
5.3 MEDIUM

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to …

Jun 25, 2026
CVE-2026-6412
4.3 MEDIUM

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

Jun 25, 2026
CVE-2026-56445
9.1 CRITICAL

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

Jun 25, 2026
CVE-2026-38640
7.5 HIGH

A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.

Jun 25, 2026
CVE-2026-38637
7.5 HIGH

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Jun 25, 2026
CVE-2026-37452
7.5 HIGH

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component

Jun 25, 2026
CVE-2026-12473
8.2 HIGH

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically …

Jun 25, 2026
CVE-2026-7531
9.8 CRITICAL

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC …

Jun 25, 2026
CVE-2026-57522
3.5 LOW

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has …

Jun 25, 2026
CVE-2026-57521
4.3 MEDIUM

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary …

Jun 25, 2026
CVE-2026-57520
7.1 HIGH

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by …

Jun 25, 2026
CVE-2026-55964
5.3 MEDIUM

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage …

Jun 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.