CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48783
4.8 MEDIUM

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side …

Jun 17, 2026
CVE-2026-48782
6.8 MEDIUM

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata …

Jun 17, 2026
CVE-2026-47340
6.5 MEDIUM

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache …

Jun 17, 2026
CVE-2026-47277
6.5 MEDIUM

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated …

Jun 17, 2026
CVE-2026-45436
6.5 MEDIUM

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

Jun 17, 2026
CVE-2026-44587
4.7 MEDIUM

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters …

Jun 17, 2026
CVE-2026-42357
6.5 MEDIUM

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler …

Jun 17, 2026
CVE-2026-41280
4.9 MEDIUM

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. …

Jun 17, 2026
CVE-2026-40724
6.5 MEDIUM

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

Jun 17, 2026
CVE-2026-40723
4.3 MEDIUM

Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.

Jun 17, 2026
CVE-2026-40722
5.5 MEDIUM

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a …

Jun 17, 2026
CVE-2026-39595
4.7 MEDIUM

Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.

Jun 17, 2026
CVE-2026-39578
5.5 MEDIUM

Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.

Jun 17, 2026
CVE-2026-39577
5.5 MEDIUM

Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.

Jun 17, 2026
CVE-2026-39433
6.5 MEDIUM

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

Jun 17, 2026
CVE-2026-2604
5.6 MEDIUM

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious …

Jun 17, 2026
CVE-2026-28587
5.5 MEDIUM

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information …

Jun 17, 2026
CVE-2026-28576
5.5 MEDIUM

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with …

Jun 17, 2026
CVE-2026-28575
5.5 MEDIUM

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial …

Jun 17, 2026
CVE-2026-27410
6.5 MEDIUM

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

Jun 17, 2026
CVE-2026-24610
4.3 MEDIUM

Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions.

Jun 17, 2026
CVE-2026-24575
4.3 MEDIUM

Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.

Jun 17, 2026
CVE-2026-12491
4.8 MEDIUM

A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF …

Jun 17, 2026
CVE-2026-12469
4.3 MEDIUM

Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

Jun 17, 2026
CVE-2026-12463
4.7 MEDIUM

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary …

Jun 17, 2026
CVE-2026-12461
6.5 MEDIUM

Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process …

Jun 17, 2026
CVE-2026-12460
4.2 MEDIUM

Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 17, 2026
CVE-2026-12459
6.1 MEDIUM

Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Jun 17, 2026
CVE-2026-12457
4.2 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Jun 17, 2026
CVE-2026-12456
4.2 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to bypass same …

Jun 17, 2026
CVE-2026-12453
4.2 MEDIUM

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 17, 2026
CVE-2026-12450
6.5 MEDIUM

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jun 17, 2026
CVE-2026-12446
4.3 MEDIUM

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jun 17, 2026
CVE-2026-12444
5.5 MEDIUM

Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitive information from process …

Jun 17, 2026
CVE-2026-12115
6.6 MEDIUM

The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Jun 17, 2026
CVE-2026-0064
5.5 MEDIUM

In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no …

Jun 17, 2026
CVE-2025-69137
6.5 MEDIUM

Subscriber Broken Access Control in Genemy <= 1.6.6 versions.

Jun 17, 2026
CVE-2025-59872
4.3 MEDIUM

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible …

Jun 17, 2026
CVE-2025-48571
4.3 MEDIUM

In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. …

Jun 17, 2026
CVE-2024-37496
4.3 MEDIUM

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.

Jun 17, 2026
CVE-2024-37210
6.5 MEDIUM

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

Jun 17, 2026
CVE-2024-35690
6.5 MEDIUM

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through …

Jun 17, 2026
CVE-2024-35648
4.3 MEDIUM

Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through …

Jun 17, 2026
CVE-2024-34810
4.3 MEDIUM

Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

Jun 17, 2026
CVE-2024-33909
5.3 MEDIUM

Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.

Jun 17, 2026
CVE-2024-33685
4.3 MEDIUM

Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.

Jun 17, 2026
CVE-2024-31435
4.3 MEDIUM

: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & …

Jun 17, 2026
CVE-2024-24709
4.3 MEDIUM

Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11.

Jun 17, 2026
CVE-2026-48776
4.2 MEDIUM

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior …

Jun 17, 2026
CVE-2026-46979
6.5 MEDIUM

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily …

Jun 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.