CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50201
6.5 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and …

Jun 17, 2026
CVE-2026-44646
5.3 MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, Context.spawn() creates a child Context for the {% …

Jun 17, 2026
CVE-2026-44645
6.5 MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can be fully bypassed by …

Jun 17, 2026
CVE-2026-44644
6.1 MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a flaw in the …

Jun 17, 2026
CVE-2026-12568
6.5 MEDIUM

The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has …

Jun 17, 2026
CVE-2026-12565
5.3 MEDIUM

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU …

Jun 17, 2026
CVE-2026-54386
6.1 MEDIUM

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping …

Jun 17, 2026
CVE-2026-48991
5.5 MEDIUM

XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local …

Jun 17, 2026
CVE-2026-48990
5.3 MEDIUM

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts …

Jun 17, 2026
CVE-2026-49133
6.5 MEDIUM

Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level privileges to read arbitrary files outside the content directory by supplying …

Jun 17, 2026
CVE-2026-48988
5.3 MEDIUM

markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the …

Jun 17, 2026
CVE-2026-48821
5.8 MEDIUM

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator …

Jun 17, 2026
CVE-2026-55201
6.8 MEDIUM

Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server …

Jun 17, 2026
CVE-2026-55199
5.9 MEDIUM

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH …

Jun 17, 2026
CVE-2026-48823
4.8 MEDIUM

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An …

Jun 17, 2026
CVE-2026-48822
5.8 MEDIUM

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in the …

Jun 17, 2026
CVE-2026-48817
5.3 MEDIUM

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and …

Jun 17, 2026
CVE-2026-32682
6.5 MEDIUM

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway …

Jun 17, 2026
CVE-2026-55198
6.5 MEDIUM

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The …

Jun 17, 2026
CVE-2026-55197
6.5 MEDIUM

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can …

Jun 17, 2026
CVE-2026-53870
5.5 MEDIUM

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local …

Jun 17, 2026
CVE-2026-9679
5.9 MEDIUM

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. …

Jun 17, 2026
CVE-2026-9678
5.9 MEDIUM

Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as …

Jun 17, 2026
CVE-2026-20265
4.3 MEDIUM

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI …

Jun 17, 2026
CVE-2026-20178
4.3 MEDIUM

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco …

Jun 17, 2026
CVE-2026-35069
5.7 MEDIUM

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with …

Jun 17, 2026
CVE-2026-20246
6.0 MEDIUM

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This …

Jun 17, 2026
CVE-2026-20220
6.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. …

Jun 17, 2026
CVE-2026-1288
5.5 MEDIUM

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful …

Jun 17, 2026
CVE-2026-12515
4.3 MEDIUM

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the …

Jun 17, 2026
CVE-2025-32748
4.3 MEDIUM

Dell PowerFlex rack, version(s) RCM 3.7/3.7, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger …

Jun 17, 2026
CVE-2026-55748
6.0 MEDIUM

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider …

Jun 17, 2026
CVE-2026-48142
4.8 MEDIUM

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both …

Jun 17, 2026
CVE-2026-48117
6.8 MEDIUM

DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an account pre-hijacking attack in which an attacker could register …

Jun 17, 2026
CVE-2026-40641
4.8 MEDIUM

Dell PowerFlex Manager, version(s) 4.6.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit …

Jun 17, 2026
CVE-2026-35162
4.3 MEDIUM

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to …

Jun 17, 2026
CVE-2026-35067
5.7 MEDIUM

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading …

Jun 17, 2026
CVE-2026-12528
5.4 MEDIUM

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes …

Jun 17, 2026
CVE-2024-47477
6.5 MEDIUM

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle …

Jun 17, 2026
CVE-2026-54817
6.5 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through …

Jun 17, 2026
CVE-2026-52716
6.5 MEDIUM

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

Jun 17, 2026
CVE-2025-15657
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

Jun 17, 2026
CVE-2026-8607
6.4 MEDIUM

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' …

Jun 17, 2026
CVE-2026-8494
6.4 MEDIUM

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions …

Jun 17, 2026
CVE-2026-8383
5.3 MEDIUM

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors …

Jun 17, 2026
CVE-2026-7850
5.9 MEDIUM

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load …

Jun 17, 2026
CVE-2026-55706
5.8 MEDIUM

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

Jun 17, 2026
CVE-2026-54196
6.8 MEDIUM

Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.

Jun 17, 2026
CVE-2026-49072
6.5 MEDIUM

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

Jun 17, 2026
CVE-2026-49071
6.5 MEDIUM

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

Jun 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.