CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-41992
7.5 HIGH

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats …

Jun 29, 2026
CVE-2026-13564
8.8 HIGH

A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a …

Jun 29, 2026
CVE-2026-13563
8.8 HIGH

A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such …

Jun 29, 2026
CVE-2026-13562
8.8 HIGH

A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This …

Jun 29, 2026
CVE-2026-13559
7.3 HIGH

A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the …

Jun 29, 2026
CVE-2026-57346
7.1 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from …

Jun 29, 2026
CVE-2026-25707
8.8 HIGH

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files …

Jun 29, 2026
CVE-2026-13601
7.1 HIGH

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open …

Jun 29, 2026
CVE-2026-13555
7.3 HIGH

A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation …

Jun 29, 2026
CVE-2026-13553
7.3 HIGH

A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of …

Jun 29, 2026
CVE-2026-13552
7.3 HIGH

A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the …

Jun 29, 2026
CVE-2026-22078
7.3 HIGH

Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

Jun 29, 2026
CVE-2026-13551
7.3 HIGH

A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of …

Jun 29, 2026
CVE-2026-13550
7.3 HIGH

A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation …

Jun 29, 2026
CVE-2026-13547
7.3 HIGH

A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of …

Jun 29, 2026
CVE-2026-13546
7.3 HIGH

A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint. …

Jun 29, 2026
CVE-2026-13545
8.8 HIGH

A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such …

Jun 29, 2026
CVE-2026-13539
8.8 HIGH

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. …

Jun 29, 2026
CVE-2026-10083
7.5 HIGH

The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site …

Jun 29, 2026
CVE-2025-2902
8.3 HIGH

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, …

Jun 29, 2026
CVE-2026-13528
7.3 HIGH

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/FileServiceImpl.java of the component AppFileController …

Jun 29, 2026
CVE-2026-13527
7.3 HIGH

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /preview4.php. Such …

Jun 29, 2026
CVE-2026-13526
7.3 HIGH

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This manipulation of …

Jun 29, 2026
CVE-2026-13521
7.3 HIGH

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such …

Jun 29, 2026
CVE-2026-13519
8.8 HIGH

A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in …

Jun 29, 2026
CVE-2026-13518
8.8 HIGH

A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads …

Jun 29, 2026
CVE-2026-13517
8.8 HIGH

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the …

Jun 29, 2026
CVE-2026-13516
8.8 HIGH

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument …

Jun 29, 2026
CVE-2026-13515
8.8 HIGH

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp …

Jun 29, 2026
CVE-2026-13500
7.3 HIGH

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action …

Jun 28, 2026
CVE-2026-13498
7.3 HIGH

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of …

Jun 28, 2026
CVE-2026-13488
7.3 HIGH

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file …

Jun 28, 2026
CVE-2026-13487
7.3 HIGH

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The manipulation of the …

Jun 28, 2026
CVE-2026-13486
7.3 HIGH

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of …

Jun 28, 2026
CVE-2026-13485
7.3 HIGH

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of …

Jun 28, 2026
CVE-2026-10646
7.4 HIGH

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS resolver query. …

Jun 28, 2026
CVE-2026-58056
7.6 HIGH

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. …

Jun 28, 2026
CVE-2026-58054
7.2 HIGH

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers the …

Jun 28, 2026
CVE-2026-58050
7.0 HIGH

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, …

Jun 28, 2026
CVE-2026-58049
8.6 HIGH

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA …

Jun 28, 2026
CVE-2026-8095
8.1 HIGH

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due …

Jun 28, 2026
CVE-2026-10643
8.7 HIGH

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen < pktinfo_len) before writing a full …

Jun 28, 2026
CVE-2026-49416
7.8 HIGH

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting …

Jun 27, 2026
CVE-2026-49414
7.8 HIGH

The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather than before. As …

Jun 27, 2026
CVE-2026-49417
7.0 HIGH

Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could …

Jun 27, 2026
CVE-2026-49413
7.1 HIGH

The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at …

Jun 27, 2026
CVE-2026-49412
7.8 HIGH

The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, then reacquired the lock. During this window …

Jun 27, 2026
CVE-2026-45258
7.8 HIGH

dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that …

Jun 27, 2026
CVE-2026-10820
8.1 HIGH

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user …

Jun 27, 2026
CVE-2023-37524
7.7 HIGH

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached …

Jun 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.