CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10864
4.3 MEDIUM

A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New …

Jun 4, 2026
CVE-2026-10860
6.5 MEDIUM

A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to …

Jun 4, 2026
CVE-2026-10811
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such …

Jun 4, 2026
CVE-2026-10861
6.1 MEDIUM

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without …

Jun 4, 2026
CVE-2026-10856
6.1 MEDIUM

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted …

Jun 4, 2026
CVE-2026-10855
4.3 MEDIUM

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a …

Jun 4, 2026
CVE-2026-10854
4.3 MEDIUM

A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder …

Jun 4, 2026
CVE-2026-10810
4.3 MEDIUM

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of …

Jun 4, 2026
CVE-2026-10809
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the …

Jun 4, 2026
CVE-2026-10808
6.3 MEDIUM

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID …

Jun 4, 2026
CVE-2026-10807
6.3 MEDIUM

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image …

Jun 4, 2026
CVE-2026-10806
6.3 MEDIUM

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post …

Jun 4, 2026
CVE-2019-25744
5.4 MEDIUM

WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in …

Jun 4, 2026
CVE-2019-25743
5.4 MEDIUM

WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post …

Jun 4, 2026
CVE-2019-25742
5.4 MEDIUM

WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field …

Jun 4, 2026
CVE-2019-25740
6.5 MEDIUM

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST …

Jun 4, 2026
CVE-2019-25739
5.4 MEDIUM

GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers …

Jun 4, 2026
CVE-2019-25737
6.1 MEDIUM

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can …

Jun 4, 2026
CVE-2019-25734
4.0 MEDIUM

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by …

Jun 4, 2026
CVE-2019-25731
6.1 MEDIUM

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can …

Jun 4, 2026
CVE-2026-10802
4.3 MEDIUM

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. …

Jun 4, 2026
CVE-2025-52606
4.3 MEDIUM

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected …

Jun 4, 2026
CVE-2026-49077
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue …

Jun 4, 2026
CVE-2026-8916
6.1 MEDIUM

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.

Jun 4, 2026
CVE-2026-50226
5.3 MEDIUM

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items …

Jun 4, 2026
CVE-2026-50224
4.9 MEDIUM

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over …

Jun 4, 2026
CVE-2026-49510
6.1 MEDIUM

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.

Jun 4, 2026
CVE-2026-47320
6.1 MEDIUM

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Jun 4, 2026
CVE-2026-47319
6.1 MEDIUM

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

Jun 4, 2026
CVE-2026-47318
6.1 MEDIUM

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.

Jun 4, 2026
CVE-2026-47306
6.1 MEDIUM

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.

Jun 4, 2026
CVE-2026-10305
6.1 MEDIUM

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Jun 4, 2026
CVE-2026-50212
6.5 MEDIUM

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

Jun 4, 2026
CVE-2026-50206
6.8 MEDIUM

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Jun 4, 2026
CVE-2026-49204
6.5 MEDIUM

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Jun 4, 2026
CVE-2026-49192
5.4 MEDIUM

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

Jun 4, 2026
CVE-2026-50219
4.9 MEDIUM

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy …

Jun 4, 2026
CVE-2026-10805
6.7 MEDIUM

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A …

Jun 4, 2026
CVE-2026-48681
5.9 MEDIUM

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

Jun 4, 2026
CVE-2026-44917
4.9 MEDIUM

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

Jun 4, 2026
CVE-2026-10597
5.3 MEDIUM

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email …

Jun 4, 2026
CVE-2026-8653
6.5 MEDIUM

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, …

Jun 4, 2026
CVE-2026-7764
6.8 MEDIUM

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker …

Jun 4, 2026
CVE-2026-8722
6.5 MEDIUM

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources …

Jun 4, 2026
CVE-2026-46447
5.8 MEDIUM

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Jun 3, 2026
CVE-2026-37700
4.1 MEDIUM

Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by …

Jun 3, 2026
CVE-2026-26825
5.3 MEDIUM

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap …

Jun 3, 2026
CVE-2026-26824
6.5 MEDIUM

libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) …

Jun 3, 2026
CVE-2026-45702
4.4 MEDIUM

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting …

Jun 3, 2026
CVE-2026-45614
4.7 MEDIUM

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior …

Jun 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.