CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-47946
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue …

Jun 9, 2026
CVE-2026-47945
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Jun 9, 2026
CVE-2026-47944
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Jun 9, 2026
CVE-2026-47943
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Jun 9, 2026
CVE-2026-47942
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Jun 9, 2026
CVE-2026-47941
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Jun 9, 2026
CVE-2026-47939
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Jun 9, 2026
CVE-2026-47936
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Jun 9, 2026
CVE-2026-47935
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue …

Jun 9, 2026
CVE-2026-47641
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-47640
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-47639
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-47638
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-47637
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-47636
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-47287
6.5 MEDIUM

Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

Jun 9, 2026
CVE-2026-47284
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Jun 9, 2026
CVE-2026-45655
5.3 MEDIUM

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Jun 9, 2026
CVE-2026-45650
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45647
5.5 MEDIUM

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-45634
5.5 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-45608
6.8 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-45606
5.5 MEDIUM

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

Jun 9, 2026
CVE-2026-45604
5.5 MEDIUM

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-45595
5.4 MEDIUM

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

Jun 9, 2026
CVE-2026-45594
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-45502
5.0 MEDIUM

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Jun 9, 2026
CVE-2026-45501
6.5 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45500
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45491
6.2 MEDIUM

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

Jun 9, 2026
CVE-2026-45483
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45479
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45468
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45467
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45465
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45464
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45462
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45460
4.7 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-45454
6.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-45453
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-45446
4.8 MEDIUM

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing …

Jun 9, 2026
CVE-2026-44821
5.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-44814
5.5 MEDIUM

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-44805
5.5 MEDIUM

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

Jun 9, 2026
CVE-2026-42973
5.5 MEDIUM

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-42972
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-42971
5.5 MEDIUM

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-42970
5.5 MEDIUM

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-42969
5.5 MEDIUM

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-42968
5.5 MEDIUM

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

Jun 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.