CVE Database

52246+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-46739
5.3 MEDIUM

Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources …

Jun 4, 2026
CVE-2026-41178
5.3 MEDIUM

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and …

Jun 4, 2026
CVE-2026-40930
5.4 MEDIUM

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard …

Jun 4, 2026
CVE-2026-10815
6.3 MEDIUM

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard …

Jun 4, 2026
CVE-2026-10814
4.5 MEDIUM

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID …

Jun 4, 2026
CVE-2026-47707
5.3 MEDIUM

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect …

Jun 4, 2026
CVE-2026-47706
5.3 MEDIUM

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to …

Jun 4, 2026
CVE-2026-36180
4.6 MEDIUM

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for …

Jun 4, 2026
CVE-2026-36178
4.6 MEDIUM

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and …

Jun 4, 2026
CVE-2026-36175
6.8 MEDIUM

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence …

Jun 4, 2026
CVE-2026-36174
4.6 MEDIUM

GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers …

Jun 4, 2026
CVE-2026-10864
4.3 MEDIUM

A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New …

Jun 4, 2026
CVE-2026-10860
6.5 MEDIUM

A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to …

Jun 4, 2026
CVE-2026-10811
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such …

Jun 4, 2026
CVE-2026-10861
6.1 MEDIUM

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without …

Jun 4, 2026
CVE-2026-10856
6.1 MEDIUM

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted …

Jun 4, 2026
CVE-2026-10855
4.3 MEDIUM

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a …

Jun 4, 2026
CVE-2026-10854
4.3 MEDIUM

A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder …

Jun 4, 2026
CVE-2026-10810
4.3 MEDIUM

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of …

Jun 4, 2026
CVE-2026-10809
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the …

Jun 4, 2026
CVE-2026-10808
6.3 MEDIUM

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID …

Jun 4, 2026
CVE-2026-10807
6.3 MEDIUM

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image …

Jun 4, 2026
CVE-2026-10806
6.3 MEDIUM

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post …

Jun 4, 2026
CVE-2019-25744
5.4 MEDIUM

WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in …

Jun 4, 2026
CVE-2019-25743
5.4 MEDIUM

WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post …

Jun 4, 2026
CVE-2019-25742
5.4 MEDIUM

WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field …

Jun 4, 2026
CVE-2019-25740
6.5 MEDIUM

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST …

Jun 4, 2026
CVE-2019-25739
5.4 MEDIUM

GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers …

Jun 4, 2026
CVE-2019-25737
6.1 MEDIUM

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can …

Jun 4, 2026
CVE-2019-25734
4.0 MEDIUM

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by …

Jun 4, 2026
CVE-2019-25731
6.1 MEDIUM

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can …

Jun 4, 2026
CVE-2026-10802
4.3 MEDIUM

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. …

Jun 4, 2026
CVE-2025-52606
4.3 MEDIUM

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected …

Jun 4, 2026
CVE-2026-49077
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue …

Jun 4, 2026
CVE-2026-8916
6.1 MEDIUM

Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.

Jun 4, 2026
CVE-2026-50226
5.3 MEDIUM

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items …

Jun 4, 2026
CVE-2026-50224
4.9 MEDIUM

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over …

Jun 4, 2026
CVE-2026-49510
6.1 MEDIUM

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.

Jun 4, 2026
CVE-2026-47320
6.1 MEDIUM

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Jun 4, 2026
CVE-2026-47319
6.1 MEDIUM

Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.

Jun 4, 2026
CVE-2026-47318
6.1 MEDIUM

Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.

Jun 4, 2026
CVE-2026-47306
6.1 MEDIUM

Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.

Jun 4, 2026
CVE-2026-10305
6.1 MEDIUM

Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Jun 4, 2026
CVE-2026-50212
6.5 MEDIUM

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

Jun 4, 2026
CVE-2026-50206
6.8 MEDIUM

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Jun 4, 2026
CVE-2026-49204
6.5 MEDIUM

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Jun 4, 2026
CVE-2026-49192
5.4 MEDIUM

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

Jun 4, 2026
CVE-2026-50219
4.9 MEDIUM

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy …

Jun 4, 2026
CVE-2026-10805
6.7 MEDIUM

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A …

Jun 4, 2026
CVE-2026-48681
5.9 MEDIUM

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

Jun 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.