CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50015
7.3 HIGH

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch …

Jun 25, 2026
CVE-2026-49839
7.1 HIGH

jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds …

Jun 25, 2026
CVE-2026-48995
7.5 HIGH

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it …

Jun 25, 2026
CVE-2026-11999
7.5 HIGH

X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra whose application calls X509_verify_cert() with caller-supplied untrusted …

Jun 25, 2026
CVE-2026-9800
8.1 HIGH

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access …

Jun 25, 2026
CVE-2026-9099
7.7 HIGH

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited …

Jun 25, 2026
CVE-2026-9086
7.3 HIGH

A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass …

Jun 25, 2026
CVE-2026-56123
8.1 HIGH

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting …

Jun 25, 2026
CVE-2026-55412
8.3 HIGH

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in …

Jun 25, 2026
CVE-2026-55092
7.5 HIGH

Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the …

Jun 25, 2026
CVE-2026-54033
7.7 HIGH

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-compatible API endpoints by setting …

Jun 25, 2026
CVE-2026-54030
8.0 HIGH

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter …

Jun 25, 2026
CVE-2026-45233
8.1 HIGH

HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequences in the …

Jun 25, 2026
CVE-2026-13351
7.5 HIGH

Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number of maliciously fragmented IPv6 packets. When …

Jun 25, 2026
CVE-2026-9717
7.2 HIGH

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, …

Jun 25, 2026
CVE-2026-9716
7.5 HIGH

CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received …

Jun 25, 2026
CVE-2026-57456
7.8 HIGH

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class …

Jun 25, 2026
CVE-2026-57455
7.8 HIGH

Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell …

Jun 25, 2026
CVE-2026-55895
7.8 HIGH

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) …

Jun 25, 2026
CVE-2026-55693
7.8 HIGH

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file …

Jun 25, 2026
CVE-2026-55477
7.2 HIGH

3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary …

Jun 25, 2026
CVE-2026-12844
7.5 HIGH

List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() collects the values returned by the block into a …

Jun 25, 2026
CVE-2026-57435
7.5 HIGH

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby …

Jun 25, 2026
CVE-2026-57434
7.5 HIGH

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods …

Jun 25, 2026
CVE-2026-57236
8.2 HIGH

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a …

Jun 25, 2026
CVE-2026-57235
8.2 HIGH

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested …

Jun 25, 2026
CVE-2026-46735
7.8 HIGH

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command …

Jun 25, 2026
CVE-2026-56122
7.5 HIGH

Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sending HTTP GET requests with dot-dot-slash …

Jun 25, 2026
CVE-2026-56071
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.

Jun 25, 2026
CVE-2026-56054
7.7 HIGH

Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.

Jun 25, 2026
CVE-2026-56053
8.8 HIGH

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

Jun 25, 2026
CVE-2026-56051
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

Jun 25, 2026
CVE-2026-56049
8.5 HIGH

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

Jun 25, 2026
CVE-2026-56042
7.1 HIGH

Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

Jun 25, 2026
CVE-2026-56014
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

Jun 25, 2026
CVE-2026-56006
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.

Jun 25, 2026
CVE-2026-56005
7.1 HIGH

Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.

Jun 25, 2026
CVE-2026-54848
8.3 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square …

Jun 25, 2026
CVE-2026-54845
8.1 HIGH

Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

Jun 25, 2026
CVE-2026-54844
7.5 HIGH

Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.

Jun 25, 2026
CVE-2026-54842
8.1 HIGH

Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.

Jun 25, 2026
CVE-2026-54841
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.

Jun 25, 2026
CVE-2026-54838
8.5 HIGH

Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

Jun 25, 2026
CVE-2026-54830
7.5 HIGH

Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

Jun 25, 2026
CVE-2026-54829
7.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. …

Jun 25, 2026
CVE-2026-54828
7.5 HIGH

Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

Jun 25, 2026
CVE-2026-54822
8.5 HIGH

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

Jun 25, 2026
CVE-2026-54821
7.4 HIGH

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

Jun 25, 2026
CVE-2026-49506
7.2 HIGH

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A …

Jun 25, 2026
CVE-2026-47151
7.1 HIGH

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is …

Jun 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.