CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-53436
4.3 MEDIUM

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative …

Jun 10, 2026
CVE-2026-52759
5.5 MEDIUM

Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can …

Jun 10, 2026
CVE-2026-52757
4.4 MEDIUM

Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a …

Jun 10, 2026
CVE-2026-52756
4.8 MEDIUM

Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations …

Jun 10, 2026
CVE-2026-52753
5.5 MEDIUM

Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol …

Jun 10, 2026
CVE-2026-49496
6.1 MEDIUM

Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vector. Attackers can trigger memory corruption by …

Jun 10, 2026
CVE-2026-49495
5.5 MEDIUM

Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when traversing Mach-O binary export tries. A crafted Mach-O …

Jun 10, 2026
CVE-2026-11853
6.5 MEDIUM

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that …

Jun 10, 2026
CVE-2026-11852
6.5 MEDIUM

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create …

Jun 10, 2026
CVE-2026-9019
6.4 MEDIUM

The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, and including, …

Jun 10, 2026
CVE-2026-8853
4.4 MEDIUM

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 …

Jun 10, 2026
CVE-2026-8613
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, …

Jun 10, 2026
CVE-2025-8444
6.4 MEDIUM

The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the …

Jun 10, 2026
CVE-2026-24720
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, …

Jun 10, 2026
CVE-2026-24717
6.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Jun 10, 2026
CVE-2026-22899
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit …

Jun 10, 2026
CVE-2025-62851
4.4 MEDIUM

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability …

Jun 10, 2026
CVE-2026-46532
4.6 MEDIUM

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid …

Jun 10, 2026
CVE-2026-45160
6.5 MEDIUM

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the …

Jun 10, 2026
CVE-2026-53675
4.3 MEDIUM

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend …

Jun 10, 2026
CVE-2026-47838
6.8 MEDIUM

SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully …

Jun 10, 2026
CVE-2026-46543
5.3 MEDIUM

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash …

Jun 10, 2026
CVE-2026-46542
4.3 MEDIUM

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability exists in …

Jun 10, 2026
CVE-2026-46540
6.5 MEDIUM

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a fork …

Jun 10, 2026
CVE-2026-46539
5.9 MEDIUM

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven …

Jun 10, 2026
CVE-2026-46411
6.5 MEDIUM

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of their …

Jun 10, 2026
CVE-2026-44505
5.3 MEDIUM

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). …

Jun 10, 2026
CVE-2026-41837
5.3 MEDIUM

Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. …

Jun 10, 2026
CVE-2026-41730
5.3 MEDIUM

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data …

Jun 10, 2026
CVE-2026-41727
6.5 MEDIUM

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted …

Jun 10, 2026
CVE-2026-41726
6.5 MEDIUM

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually …

Jun 10, 2026
CVE-2026-41721
5.9 MEDIUM

Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction …

Jun 10, 2026
CVE-2026-41719
6.4 MEDIUM

A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates …

Jun 10, 2026
CVE-2026-41714
4.0 MEDIUM

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: …

Jun 10, 2026
CVE-2026-41711
5.9 MEDIUM

Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: …

Jun 10, 2026
CVE-2026-41706
6.1 MEDIUM

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination …

Jun 10, 2026
CVE-2026-41701
4.4 MEDIUM

Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through …

Jun 10, 2026
CVE-2026-41697
4.8 MEDIUM

Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An …

Jun 10, 2026
CVE-2026-41696
5.9 MEDIUM

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply …

Jun 10, 2026
CVE-2026-41008
6.1 MEDIUM

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri …

Jun 10, 2026
CVE-2026-40991
5.9 MEDIUM

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting …

Jun 10, 2026
CVE-2026-9754
6.5 MEDIUM

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command

Jun 9, 2026
CVE-2026-9752
6.5 MEDIUM

An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing …

Jun 9, 2026
CVE-2026-9751
5.5 MEDIUM

The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

Jun 9, 2026
CVE-2026-9750
6.5 MEDIUM

An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query …

Jun 9, 2026
CVE-2026-9749
6.5 MEDIUM

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single …

Jun 9, 2026
CVE-2026-9748
6.5 MEDIUM

The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general …

Jun 9, 2026
CVE-2026-9747
6.5 MEDIUM

Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.

Jun 9, 2026
CVE-2026-9746
6.5 MEDIUM

When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges …

Jun 9, 2026
CVE-2026-9743
6.5 MEDIUM

In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on …

Jun 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.