CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-46977
3.2 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows …

Jun 17, 2026
CVE-2026-46874
3.2 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high …

Jun 17, 2026
CVE-2026-46816
3.2 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows …

Jun 17, 2026
CVE-2026-46815
3.2 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows …

Jun 17, 2026
CVE-2026-0158
3.3 LOW

In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with …

Jun 16, 2026
CVE-2026-0145
3.3 LOW

In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no …

Jun 16, 2026
CVE-2026-0142
3.3 LOW

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with …

Jun 16, 2026
CVE-2026-0134
3.3 LOW

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could …

Jun 16, 2026
CVE-2026-0130
3.5 LOW

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no …

Jun 16, 2026
CVE-2026-0129
3.5 LOW

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. …

Jun 16, 2026
CVE-2026-10636
3.7 LOW

In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet had been handed …

Jun 16, 2026
CVE-2026-48709
3.7 LOW

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform …

Jun 15, 2026
CVE-2026-12211
2.7 LOW

A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component …

Jun 15, 2026
CVE-2026-12202
2.4 LOW

A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. …

Jun 15, 2026
CVE-2026-9062
3.4 LOW

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators …

Jun 13, 2026
CVE-2026-9061
3.5 LOW

The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator …

Jun 13, 2026
CVE-2026-53837
3.7 LOW

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM …

Jun 12, 2026
CVE-2026-53607
3.7 LOW

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a documented SEO …

Jun 12, 2026
CVE-2026-12130
3.5 LOW

A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component …

Jun 12, 2026
CVE-2026-12129
3.5 LOW

A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the …

Jun 12, 2026
CVE-2026-12065
1.8 LOW

A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView …

Jun 12, 2026
CVE-2026-9269
3.5 LOW

The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high …

Jun 12, 2026
CVE-2026-12032
3.1 LOW

Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site …

Jun 11, 2026
CVE-2026-12017
3.1 LOW

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

Jun 11, 2026
CVE-2026-53809
3.8 LOW

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical …

Jun 11, 2026
CVE-2026-44489
3.7 LOW

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are …

Jun 11, 2026
CVE-2026-11956
3.7 LOW

A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing …

Jun 11, 2026
CVE-2026-9694
2.6 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain …

Jun 11, 2026
CVE-2026-6976
3.7 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain …

Jun 11, 2026
CVE-2026-3553
3.1 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain …

Jun 11, 2026
CVE-2026-41000
3.7 LOW

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation …

Jun 11, 2026
CVE-2026-47712
3.3 LOW

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=...) derives each patch …

Jun 10, 2026
CVE-2026-48011
3.7 LOW

Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing …

Jun 10, 2026
CVE-2026-45380
3.6 LOW

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, a one-byte off-by-one error in SafeOutPathBuilder::restoreSymlink() allows …

Jun 10, 2026
CVE-2022-48575
3.5 LOW

A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue …

Jun 10, 2026
CVE-2026-50568
3.6 LOW

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated …

Jun 10, 2026
CVE-2026-49497
3.3 LOW

Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers …

Jun 10, 2026
CVE-2024-58350
2.9 LOW

Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initialization order of the SleighArchitecture::translators and XmlArchitectureCapability singletons. …

Jun 10, 2026
CVE-2026-9060
3.5 LOW

The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store …

Jun 10, 2026
CVE-2026-41694
3.7 LOW

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able …

Jun 10, 2026
CVE-2026-48289
3.5 LOW

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature …

Jun 9, 2026
CVE-2026-48288
3.5 LOW

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature …

Jun 9, 2026
CVE-2026-45642
3.9 LOW

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

Jun 9, 2026
CVE-2026-45485
3.3 LOW

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-45466
3.3 LOW

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Jun 9, 2026
CVE-2026-45459
3.3 LOW

Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-45455
3.3 LOW

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Jun 9, 2026
CVE-2026-42770
3.7 LOW

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: …

Jun 9, 2026
CVE-2026-42768
3.7 LOW

Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and …

Jun 9, 2026
CVE-2026-11792
3.3 LOW

A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password …

Jun 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.