CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10637
5.9 MEDIUM

subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network stack's ownership contract (include/zephyr/net/net_core.h, and the explicit warning in subsys/net/ip/net_core.c:453-460 'do …

Jun 16, 2026
CVE-2024-22447
6.7 MEDIUM

Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious dll., …

Jun 16, 2026
CVE-2026-53900
4.3 MEDIUM

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies …

Jun 16, 2026
CVE-2026-53899
6.5 MEDIUM

Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging …

Jun 16, 2026
CVE-2026-12330
5.4 MEDIUM

Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12329
5.3 MEDIUM

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12325
6.5 MEDIUM

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12323
5.4 MEDIUM

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12322
5.4 MEDIUM

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12321
5.4 MEDIUM

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12320
4.3 MEDIUM

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12319
6.5 MEDIUM

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12313
4.7 MEDIUM

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12311
4.7 MEDIUM

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12309
6.5 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12308
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12307
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12306
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12303
4.3 MEDIUM

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12302
6.5 MEDIUM

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12301
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12300
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12299
5.4 MEDIUM

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and …

Jun 16, 2026
CVE-2026-12298
5.4 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-54197
6.5 MEDIUM

Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

Jun 16, 2026
CVE-2026-54190
6.5 MEDIUM

Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

Jun 16, 2026
CVE-2026-52714
5.9 MEDIUM

Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.

Jun 16, 2026
CVE-2026-40809
6.5 MEDIUM

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.

Jun 16, 2026
CVE-2026-2381
6.5 MEDIUM

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function …

Jun 16, 2026
CVE-2026-10093
6.4 MEDIUM

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all …

Jun 16, 2026
CVE-2025-9912
6.3 MEDIUM

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands …

Jun 16, 2026
CVE-2026-9187
5.3 MEDIUM

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due …

Jun 16, 2026
CVE-2026-5149
6.5 MEDIUM

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX …

Jun 16, 2026
CVE-2026-50255
6.7 MEDIUM

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed …

Jun 16, 2026
CVE-2026-10780
4.3 MEDIUM

The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to …

Jun 16, 2026
CVE-2026-10635
6.3 MEDIUM

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded …

Jun 16, 2026
CVE-2025-10262
6.3 MEDIUM

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user …

Jun 16, 2026
CVE-2026-6964
5.3 MEDIUM

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to …

Jun 16, 2026
CVE-2026-42014
6.6 MEDIUM

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when …

Jun 16, 2026
CVE-2026-1767
5.6 MEDIUM

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow …

Jun 16, 2026
CVE-2026-1766
5.6 MEDIUM

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when …

Jun 16, 2026
CVE-2026-1765
5.6 MEDIUM

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially …

Jun 16, 2026
CVE-2026-1764
5.6 MEDIUM

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds …

Jun 16, 2026
CVE-2026-12162
5.5 MEDIUM

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via …

Jun 16, 2026
CVE-2026-9262
6.5 MEDIUM

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9261
6.8 MEDIUM

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9260
6.2 MEDIUM

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9259
6.5 MEDIUM

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9258
6.5 MEDIUM

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-48157
6.1 MEDIUM

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses …

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.