CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11701
5.4 MEDIUM

Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

Jun 9, 2026
CVE-2026-11696
5.3 MEDIUM

Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially …

Jun 9, 2026
CVE-2026-11695
4.3 MEDIUM

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jun 9, 2026
CVE-2026-11685
4.3 MEDIUM

Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

Jun 9, 2026
CVE-2026-11678
5.3 MEDIUM

Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information …

Jun 9, 2026
CVE-2026-11669
5.3 MEDIUM

Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to …

Jun 9, 2026
CVE-2026-11668
4.3 MEDIUM

Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video …

Jun 9, 2026
CVE-2026-11666
5.4 MEDIUM

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML …

Jun 9, 2026
CVE-2026-11665
4.3 MEDIUM

Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted …

Jun 9, 2026
CVE-2026-11658
6.5 MEDIUM

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 9, 2026
CVE-2026-11653
6.5 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Jun 9, 2026
CVE-2026-11628
6.8 MEDIUM

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the …

Jun 9, 2026
CVE-2026-11585
6.3 MEDIUM

A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument …

Jun 8, 2026
CVE-2026-11584
6.3 MEDIUM

A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument …

Jun 8, 2026
CVE-2026-11583
6.3 MEDIUM

A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the …

Jun 8, 2026
CVE-2026-11559
6.3 MEDIUM

A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results …

Jun 8, 2026
CVE-2026-11558
6.3 MEDIUM

A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of …

Jun 8, 2026
CVE-2026-10787
4.3 MEDIUM

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a …

Jun 8, 2026
CVE-2026-10786
6.5 MEDIUM

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via …

Jun 8, 2026
CVE-2026-10544
6.5 MEDIUM

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a …

Jun 8, 2026
CVE-2026-11554
4.3 MEDIUM

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least …

Jun 8, 2026
CVE-2026-11552
5.3 MEDIUM

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue …

Jun 8, 2026
CVE-2026-45581
5.5 MEDIUM

fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service …

Jun 8, 2026
CVE-2026-39908
6.5 MEDIUM

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by …

Jun 8, 2026
CVE-2026-11611
6.5 MEDIUM

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync …

Jun 8, 2026
CVE-2026-11533
5.4 MEDIUM

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of …

Jun 8, 2026
CVE-2026-11532
6.3 MEDIUM

A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record …

Jun 8, 2026
CVE-2026-46443
6.5 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with …

Jun 8, 2026
CVE-2026-44119
5.5 MEDIUM

Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. …

Jun 8, 2026
CVE-2026-43951
6.5 MEDIUM

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

Jun 8, 2026
CVE-2026-42862
5.0 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists …

Jun 8, 2026
CVE-2026-29170
6.1 MEDIUM

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via …

Jun 8, 2026
CVE-2026-11529
6.3 MEDIUM

A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql …

Jun 8, 2026
CVE-2020-37248
6.5 MEDIUM

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials …

Jun 8, 2026
CVE-2026-25558
4.8 MEDIUM

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted …

Jun 8, 2026
CVE-2026-11521
6.3 MEDIUM

A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the component Transaction …

Jun 8, 2026
CVE-2026-11519
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the …

Jun 8, 2026
CVE-2026-11518
4.3 MEDIUM

A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The …

Jun 8, 2026
CVE-2026-11516
5.5 MEDIUM

A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the …

Jun 8, 2026
CVE-2026-9549
4.8 MEDIUM

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure …

Jun 8, 2026
CVE-2026-8833
5.4 MEDIUM

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass …

Jun 8, 2026
CVE-2026-8078
4.8 MEDIUM

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global …

Jun 8, 2026
CVE-2026-7765
5.3 MEDIUM

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, …

Jun 8, 2026
CVE-2026-7186
5.4 MEDIUM

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to …

Jun 8, 2026
CVE-2026-11515
5.3 MEDIUM

A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file …

Jun 8, 2026
CVE-2026-11514
6.3 MEDIUM

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of …

Jun 8, 2026
CVE-2026-11513
6.3 MEDIUM

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date …

Jun 8, 2026
CVE-2026-11512
4.3 MEDIUM

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of …

Jun 8, 2026
CVE-2026-3011
6.4 MEDIUM

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions …

Jun 8, 2026
CVE-2026-11569
5.4 MEDIUM

A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload …

Jun 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.