CVE Database

135932+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-47306
6.1 MEDIUM

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.

Jun 4, 2026
CVE-2026-10800
3.6 LOW

A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the …

Jun 4, 2026
CVE-2026-10305
6.1 MEDIUM

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Jun 4, 2026
CVE-2026-50213
7.5 HIGH

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

Jun 4, 2026
CVE-2026-50212
6.5 MEDIUM

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

Jun 4, 2026
CVE-2026-50211
9.8 CRITICAL

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

Jun 4, 2026
CVE-2026-50210
7.5 HIGH

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.

Jun 4, 2026
CVE-2026-50209
7.8 HIGH

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.

Jun 4, 2026
CVE-2026-50208
9.4 CRITICAL

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

Jun 4, 2026
CVE-2026-50207
7.8 HIGH

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.

Jun 4, 2026
CVE-2026-3820
7.2 HIGH

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain administrator privileges and inject specially crafted characters into …

Jun 4, 2026
CVE-2026-50206
6.8 MEDIUM

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Jun 4, 2026
CVE-2026-50205
8.2 HIGH

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

Jun 4, 2026
CVE-2026-49204
6.5 MEDIUM

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Jun 4, 2026
CVE-2026-49203
8.3 HIGH

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

Jun 4, 2026
CVE-2026-49202
8.6 HIGH

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.

Jun 4, 2026
CVE-2026-49194
8.8 HIGH

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.

Jun 4, 2026
CVE-2026-49193
7.5 HIGH

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

Jun 4, 2026
CVE-2026-49192
5.4 MEDIUM

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

Jun 4, 2026
CVE-2026-49191
9.8 CRITICAL

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Jun 4, 2026
CVE-2026-49190
8.8 HIGH

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.

Jun 4, 2026
CVE-2026-50219
4.9 MEDIUM

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy …

Jun 4, 2026
CVE-2026-49189
7.8 HIGH

Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.

Jun 4, 2026
CVE-2026-49188
9.8 CRITICAL

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root …

Jun 4, 2026
CVE-2026-49187
7.5 HIGH

The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

Jun 4, 2026
CVE-2026-10805
6.7 MEDIUM

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A …

Jun 4, 2026
CVE-2026-49186
9.8 CRITICAL

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to …

Jun 4, 2026
CVE-2026-49185
9.8 CRITICAL

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Jun 4, 2026
CVE-2026-48681
5.9 MEDIUM

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

Jun 4, 2026
CVE-2026-44917
4.9 MEDIUM

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

Jun 4, 2026
CVE-2026-41283
9.9 CRITICAL

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to …

Jun 4, 2026
CVE-2026-41010
8.2 HIGH

ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array …

Jun 4, 2026
CVE-2026-8829
7.5 HIGH

HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV …

Jun 4, 2026
CVE-2026-41860
8.8 HIGH

CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an …

Jun 4, 2026
CVE-2026-41859
7.8 HIGH

A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with …

Jun 4, 2026
CVE-2026-41858
7.5 HIGH

Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a …

Jun 4, 2026
CVE-2026-41011
8.2 HIGH

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The …

Jun 4, 2026
CVE-2026-10597
5.3 MEDIUM

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email …

Jun 4, 2026
CVE-2026-8653
6.5 MEDIUM

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, …

Jun 4, 2026
CVE-2026-7764
6.8 MEDIUM

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker …

Jun 4, 2026
CVE-2026-10737
7.5 HIGH

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in …

Jun 4, 2026
CVE-2026-8722
6.5 MEDIUM

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources …

Jun 4, 2026
CVE-2026-10783
2.5 LOW

A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation …

Jun 4, 2026
CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 3, 2026
CVE-2026-10777
7.3 HIGH

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component …

Jun 3, 2026
CVE-2026-10775
3.6 LOW

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation …

Jun 3, 2026
CVE-2026-46447
5.8 MEDIUM

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Jun 3, 2026
CVE-2026-22055

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Jun 3, 2026
CVE-2026-22054

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Jun 3, 2026
CVE-2026-10771
7.3 HIGH

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation …

Jun 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.