CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42507
5.3 MEDIUM

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading …

Jun 2, 2026
CVE-2026-41412
4.9 MEDIUM

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a …

Jun 2, 2026
CVE-2026-27145
6.5 MEDIUM

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same …

Jun 2, 2026
CVE-2026-25861
5.9 MEDIUM

QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of …

Jun 2, 2026
CVE-2026-10688
5.5 MEDIUM

A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py. This manipulation of the …

Jun 2, 2026
CVE-2026-10662
6.3 MEDIUM

A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element is the function requests.get of the file src/blender_mcp/server.py of the component ZIP …

Jun 2, 2026
CVE-2026-35212
6.1 MEDIUM

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering …

Jun 2, 2026
CVE-2026-10661
4.3 MEDIUM

A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The manipulation of the argument …

Jun 2, 2026
CVE-2026-10650
5.3 MEDIUM

A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH …

Jun 2, 2026
CVE-2025-15653
6.8 MEDIUM

Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to …

Jun 2, 2026
CVE-2026-49144
6.5 MEDIUM

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. …

Jun 2, 2026
CVE-2026-45289
5.3 MEDIUM

CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526-15, CloudburstMC Protocol is partially missing validation for FULL type authentication tokens …

Jun 2, 2026
CVE-2026-41569
6.1 MEDIUM

authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather …

Jun 2, 2026
CVE-2026-10624
4.3 MEDIUM

A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the …

Jun 2, 2026
CVE-2026-5074
6.5 MEDIUM

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, …

Jun 2, 2026
CVE-2026-48682
5.9 MEDIUM

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) …

Jun 2, 2026
CVE-2026-40181
6.1 MEDIUM

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger …

Jun 2, 2026
CVE-2026-35049
6.5 MEDIUM

wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an …

Jun 2, 2026
CVE-2026-34993
6.4 MEDIUM

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. …

Jun 2, 2026
CVE-2026-33553
6.1 MEDIUM

Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.

Jun 2, 2026
CVE-2026-30586
6.1 MEDIUM

Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo …

Jun 2, 2026
CVE-2026-10702
4.3 MEDIUM

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

Jun 2, 2026
CVE-2026-10616
4.3 MEDIUM

A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the component …

Jun 2, 2026
CVE-2026-10584
5.9 MEDIUM

Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive …

Jun 2, 2026
CVE-2021-4479
4.0 MEDIUM

Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending …

Jun 2, 2026
CVE-2019-25724
6.5 MEDIUM

Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of service vulnerability that allows attackers with access to …

Jun 2, 2026
CVE-2019-25723
4.0 MEDIUM

Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by …

Jun 2, 2026
CVE-2019-25721
6.5 MEDIUM

Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of service vulnerability that allows network-adjacent attackers to repeatedly …

Jun 2, 2026
CVE-2026-49943
6.3 MEDIUM

CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses …

Jun 2, 2026
CVE-2026-42073
6.5 MEDIUM

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a …

Jun 2, 2026
CVE-2026-40713
6.1 MEDIUM

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, …

Jun 2, 2026
CVE-2026-33244
5.4 MEDIUM

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` …

Jun 2, 2026
CVE-2026-1871
6.5 MEDIUM

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can …

Jun 2, 2026
CVE-2026-9590
5.3 MEDIUM

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset …

Jun 2, 2026
CVE-2026-9522
5.4 MEDIUM

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network …

Jun 2, 2026
CVE-2026-7299
6.3 MEDIUM

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS …

Jun 2, 2026
CVE-2026-45684
4.9 MEDIUM

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by …

Jun 2, 2026
CVE-2026-45682
5.1 MEDIUM

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never …

Jun 2, 2026
CVE-2026-45681
5.9 MEDIUM

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer …

Jun 2, 2026
CVE-2026-45680
5.9 MEDIUM

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping …

Jun 2, 2026
CVE-2026-45679
6.5 MEDIUM

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status …

Jun 2, 2026
CVE-2026-45676
5.5 MEDIUM

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF parser trusts section offsets, counts, and string …

Jun 2, 2026
CVE-2026-45554
5.3 MEDIUM

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that …

Jun 2, 2026
CVE-2026-38978
5.3 MEDIUM

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

Jun 2, 2026
CVE-2026-35718
6.5 MEDIUM

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via …

Jun 2, 2026
CVE-2026-35716
6.3 MEDIUM

A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an …

Jun 2, 2026
CVE-2026-34460
5.4 MEDIUM

NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging …

Jun 2, 2026
CVE-2026-49782
5.4 MEDIUM

Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through …

Jun 2, 2026
CVE-2026-41918
5.7 MEDIUM

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an …

Jun 2, 2026
CVE-2026-35717
6.3 MEDIUM

A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a …

Jun 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.