CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11786
1.9 LOW

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing …

Jun 9, 2026
CVE-2026-41986
2.4 LOW

Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2026-41974
3.6 LOW

Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

Jun 9, 2026
CVE-2026-8981
3.5 LOW

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code …

Jun 9, 2026
CVE-2026-41852
3.7 LOW

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an …

Jun 9, 2026
CVE-2026-41848
3.7 LOW

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then …

Jun 9, 2026
CVE-2026-44743
3.7 LOW

Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the …

Jun 9, 2026
CVE-2026-11691
3.1 LOW

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process …

Jun 9, 2026
CVE-2026-11686
3.1 LOW

Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process …

Jun 9, 2026
CVE-2026-11684
3.1 LOW

Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility process to leak cross-origin data …

Jun 9, 2026
CVE-2026-11675
3.1 LOW

Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin …

Jun 9, 2026
CVE-2026-11555
3.7 LOW

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation …

Jun 8, 2026
CVE-2026-11534
3.5 LOW

A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of …

Jun 8, 2026
CVE-2026-11520
3.5 LOW

A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes …

Jun 8, 2026
CVE-2026-11511
3.5 LOW

A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute …

Jun 8, 2026
CVE-2026-11502
3.1 LOW

A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This …

Jun 8, 2026
CVE-2026-11491
2.4 LOW

A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board …

Jun 8, 2026
CVE-2026-11481
2.5 LOW

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres …

Jun 8, 2026
CVE-2026-11478
3.3 LOW

A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern …

Jun 8, 2026
CVE-2026-11468
2.4 LOW

A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation …

Jun 8, 2026
CVE-2026-11465
3.1 LOW

A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of …

Jun 7, 2026
CVE-2026-11464
3.1 LOW

A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User …

Jun 7, 2026
CVE-2026-11459
3.3 LOW

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL …

Jun 7, 2026
CVE-2026-11434
2.4 LOW

A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Plugin. This …

Jun 6, 2026
CVE-2025-12656
3.8 LOW

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in …

Jun 6, 2026
CVE-2026-11338
2.4 LOW

A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation …

Jun 5, 2026
CVE-2026-48102
3.1 LOW

7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in …

Jun 5, 2026
CVE-2026-11330
3.6 LOW

A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the component …

Jun 5, 2026
CVE-2026-11329
3.6 LOW

A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the …

Jun 5, 2026
CVE-2026-21027
3.3 LOW

Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

Jun 5, 2026
CVE-2026-9088
2.7 LOW

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the …

Jun 5, 2026
CVE-2026-11312
3.3 LOW

A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV …

Jun 5, 2026
CVE-2026-11251
3.1 LOW

Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass discretionary …

Jun 5, 2026
CVE-2026-11247
3.1 LOW

Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Jun 5, 2026
CVE-2026-11244
3.1 LOW

Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 5, 2026
CVE-2026-11240
3.1 LOW

Insufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass …

Jun 5, 2026
CVE-2026-50266
2.2 LOW

In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner …

Jun 4, 2026
CVE-2026-10813
3.6 LOW

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. …

Jun 4, 2026
CVE-2026-45739
3.1 LOW

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor …

Jun 4, 2026
CVE-2026-10812
3.6 LOW

A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component …

Jun 4, 2026
CVE-2025-62338
3.3 LOW

HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized access and may lead to information exposure.

Jun 4, 2026
CVE-2026-10804
3.6 LOW

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such …

Jun 4, 2026
CVE-2026-10803
3.6 LOW

A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest …

Jun 4, 2026
CVE-2025-52611
3.1 LOW

HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the …

Jun 4, 2026
CVE-2025-52609
3.7 LOW

HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern …

Jun 4, 2026
CVE-2025-52608
3.1 LOW

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. …

Jun 4, 2026
CVE-2026-10801
3.6 LOW

A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL …

Jun 4, 2026
CVE-2026-10800
3.6 LOW

A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the …

Jun 4, 2026
CVE-2026-10783
2.5 LOW

A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation …

Jun 4, 2026
CVE-2026-10775
3.6 LOW

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation …

Jun 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.