CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42915
5.7 MEDIUM

Incorrect calculation of buffer size in Windows TCP/IP allows an authorized attacker to deny service over an adjacent network.

Jun 9, 2026
CVE-2026-42914
5.3 MEDIUM

Windows Kerberos Denial of Service Vulnerability

Jun 9, 2026
CVE-2026-42907
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-42906
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-42903
6.5 MEDIUM

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

Jun 9, 2026
CVE-2026-42771
6.2 MEDIUM

Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, an out of …

Jun 9, 2026
CVE-2026-42769
5.3 MEDIUM

Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response …

Jun 9, 2026
CVE-2026-42767
5.9 MEDIUM

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL pointer …

Jun 9, 2026
CVE-2026-42766
5.9 MEDIUM

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to …

Jun 9, 2026
CVE-2026-42599
6.1 MEDIUM

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are …

Jun 9, 2026
CVE-2026-42573
6.1 MEDIUM

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially …

Jun 9, 2026
CVE-2026-35188
5.0 MEDIUM

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's …

Jun 9, 2026
CVE-2026-34692
5.4 MEDIUM

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue …

Jun 9, 2026
CVE-2026-33113
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jun 9, 2026
CVE-2026-28301
4.8 MEDIUM

A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.

Jun 9, 2026
CVE-2026-49938
6.5 MEDIUM

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access …

Jun 9, 2026
CVE-2025-67862
6.7 MEDIUM

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS …

Jun 9, 2026
CVE-2026-11793
4.9 MEDIUM

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack …

Jun 9, 2026
CVE-2026-11790
4.9 MEDIUM

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from …

Jun 9, 2026
CVE-2026-11789
4.9 MEDIUM

A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password …

Jun 9, 2026
CVE-2026-11788
5.9 MEDIUM

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an …

Jun 9, 2026
CVE-2026-11787
5.0 MEDIUM

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap …

Jun 9, 2026
CVE-2026-11785
4.3 MEDIUM

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be …

Jun 9, 2026
CVE-2016-20064
6.2 MEDIUM

WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include …

Jun 9, 2026
CVE-2026-52902
4.7 MEDIUM

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker …

Jun 9, 2026
CVE-2026-4058
4.3 MEDIUM

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due …

Jun 9, 2026
CVE-2026-46747
4.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in …

Jun 9, 2026
CVE-2025-40808
6.1 MEDIUM

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC …

Jun 9, 2026
CVE-2026-8677
6.4 MEDIUM

The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings …

Jun 9, 2026
CVE-2026-8599
6.4 MEDIUM

The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Content Field …

Jun 9, 2026
CVE-2026-7542
6.5 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to and including 7.0.10. This is due to three compounding …

Jun 9, 2026
CVE-2026-6899
5.6 MEDIUM

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of …

Jun 9, 2026
CVE-2026-49818
6.5 MEDIUM

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` …

Jun 9, 2026
CVE-2026-34905
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not …

Jun 9, 2026
CVE-2026-34033
5.4 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content …

Jun 9, 2026
CVE-2026-34031
6.5 MEDIUM

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied …

Jun 9, 2026
CVE-2026-33582
6.5 MEDIUM

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive …

Jun 9, 2026
CVE-2026-28262
6.0 MEDIUM

Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access …

Jun 9, 2026
CVE-2026-25699
6.1 MEDIUM

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization …

Jun 9, 2026
CVE-2026-25688
6.1 MEDIUM

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser …

Jun 9, 2026
CVE-2026-41985
5.1 MEDIUM

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Jun 9, 2026
CVE-2026-41984
5.2 MEDIUM

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Jun 9, 2026
CVE-2026-41983
4.3 MEDIUM

DoS vulnerability in the browser kernel. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2026-41982
6.4 MEDIUM

Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2026-41981
5.3 MEDIUM

Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2026-41977
5.0 MEDIUM

DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2026-41976
6.6 MEDIUM

Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 9, 2026
CVE-2026-41973
5.9 MEDIUM

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2026-41972
5.4 MEDIUM

Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2025-62858
6.5 MEDIUM

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Jun 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.