CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50892
6.5 MEDIUM

Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material …

Jun 15, 2026
CVE-2026-50876
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Jun 15, 2026
CVE-2026-49953
6.5 MEDIUM

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and …

Jun 15, 2026
CVE-2026-39197
6.5 MEDIUM

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or …

Jun 15, 2026
CVE-2026-37216
6.1 MEDIUM

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

Jun 15, 2026
CVE-2026-36933
6.8 MEDIUM

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

Jun 15, 2026
CVE-2026-36521
6.1 MEDIUM

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

Jun 15, 2026
CVE-2026-11931
5.5 MEDIUM

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or …

Jun 15, 2026
CVE-2025-70102
6.3 MEDIUM

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a …

Jun 15, 2026
CVE-2025-55663
5.5 MEDIUM

A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55661
5.5 MEDIUM

A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via …

Jun 15, 2026
CVE-2025-55660
5.5 MEDIUM

A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55652
5.5 MEDIUM

A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55650
5.5 MEDIUM

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55649
5.5 MEDIUM

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55648
5.5 MEDIUM

A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55647
5.5 MEDIUM

An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 …

Jun 15, 2026
CVE-2025-55645
5.5 MEDIUM

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2025-55644
5.5 MEDIUM

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Jun 15, 2026
CVE-2025-55643
5.5 MEDIUM

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying …

Jun 15, 2026
CVE-2025-55642
6.5 MEDIUM

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).

Jun 15, 2026
CVE-2025-55641
5.5 MEDIUM

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 15, 2026
CVE-2026-49294
6.1 MEDIUM

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to reflected cross-site scripting …

Jun 15, 2026
CVE-2026-20262
6.5 MEDIUM KEV

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or …

Jun 15, 2026
CVE-2026-9595
5.3 MEDIUM

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket …

Jun 15, 2026
CVE-2026-8683
6.5 MEDIUM

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious …

Jun 15, 2026
CVE-2026-5038
5.3 MEDIUM

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned …

Jun 15, 2026
CVE-2026-10634
4.8 MEDIUM

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. …

Jun 15, 2026
CVE-2025-15659
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

Jun 15, 2026
CVE-2025-15658
5.9 MEDIUM

Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.

Jun 15, 2026
CVE-2026-6517
6.3 MEDIUM

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop …

Jun 15, 2026
CVE-2026-48969
6.5 MEDIUM

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

Jun 15, 2026
CVE-2025-64215
6.5 MEDIUM

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before …

Jun 15, 2026
CVE-2016-20083
5.3 MEDIUM

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can …

Jun 15, 2026
CVE-2016-20082
6.2 MEDIUM

WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send …

Jun 15, 2026
CVE-2016-20080
6.2 MEDIUM

WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating …

Jun 15, 2026
CVE-2016-20079
6.2 MEDIUM

WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. …

Jun 15, 2026
CVE-2016-20078
6.2 MEDIUM

WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers …

Jun 15, 2026
CVE-2016-20077
6.2 MEDIUM

WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in …

Jun 15, 2026
CVE-2016-20074
4.3 MEDIUM

WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers …

Jun 15, 2026
CVE-2016-20070
6.4 MEDIUM

WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious …

Jun 15, 2026
CVE-2016-20067
4.3 MEDIUM

WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft …

Jun 15, 2026
CVE-2026-44188
5.3 MEDIUM

A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible …

Jun 15, 2026
CVE-2026-9278
5.4 MEDIUM

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of …

Jun 15, 2026
CVE-2026-8386
5.3 MEDIUM

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve …

Jun 15, 2026
CVE-2026-8385
5.3 MEDIUM

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing …

Jun 15, 2026
CVE-2026-12223
5.5 MEDIUM

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI …

Jun 15, 2026
CVE-2026-12219
6.3 MEDIUM

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI …

Jun 15, 2026
CVE-2026-12216
5.3 MEDIUM

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of …

Jun 15, 2026
CVE-2026-12213
4.3 MEDIUM

A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function getAccountInfo of the file server/account/src/operations.ts of the …

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.