CVE Database

52246+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60483
5.5 MEDIUM

A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Jun 1, 2026
CVE-2025-60481
5.5 MEDIUM

A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Jun 1, 2026
CVE-2025-55664
5.5 MEDIUM

A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 1, 2026
CVE-2026-9309
5.4 MEDIUM

Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior …

Jun 1, 2026
CVE-2026-9308
5.4 MEDIUM

Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string …

Jun 1, 2026
CVE-2026-34193
4.3 MEDIUM

Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the …

Jun 1, 2026
CVE-2026-10258
6.3 MEDIUM

A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument …

Jun 1, 2026
CVE-2026-10257
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of …

Jun 1, 2026
CVE-2026-10256
6.3 MEDIUM

A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name …

Jun 1, 2026
CVE-2026-10255
5.3 MEDIUM

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. …

Jun 1, 2026
CVE-2026-10254
5.3 MEDIUM

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file …

Jun 1, 2026
CVE-2026-49328
5.3 MEDIUM

Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or …

Jun 1, 2026
CVE-2026-25600
6.4 MEDIUM

The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the …

Jun 1, 2026
CVE-2026-25599
6.3 MEDIUM

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, …

Jun 1, 2026
CVE-2026-10248
4.7 MEDIUM

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of …

Jun 1, 2026
CVE-2026-8474
5.3 MEDIUM

A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute …

Jun 1, 2026
CVE-2026-49270
5.9 MEDIUM

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with …

Jun 1, 2026
CVE-2026-49267
5.9 MEDIUM

Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] …

Jun 1, 2026
CVE-2026-48726
6.5 MEDIUM

A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow …

Jun 1, 2026
CVE-2026-46764
4.3 MEDIUM

The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, …

Jun 1, 2026
CVE-2026-46605
4.3 MEDIUM

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache …

Jun 1, 2026
CVE-2026-42360
6.5 MEDIUM

A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON …

Jun 1, 2026
CVE-2026-42358
6.5 MEDIUM

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when …

Jun 1, 2026
CVE-2026-42253
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API …

Jun 1, 2026
CVE-2026-41017
5.9 MEDIUM

Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. …

Jun 1, 2026
CVE-2026-41014
4.3 MEDIUM

The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate …

Jun 1, 2026
CVE-2026-40861
6.5 MEDIUM

A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process …

Jun 1, 2026
CVE-2026-10517
5.8 MEDIUM

A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. …

Jun 1, 2026
CVE-2026-10242
6.3 MEDIUM

A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument …

Jun 1, 2026
CVE-2026-10241
6.3 MEDIUM

A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug …

Jun 1, 2026
CVE-2026-10240
6.3 MEDIUM

A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument …

Jun 1, 2026
CVE-2026-10239
6.3 MEDIUM

A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead …

Jun 1, 2026
CVE-2026-10237
4.7 MEDIUM

A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management …

Jun 1, 2026
CVE-2026-45192
6.5 MEDIUM

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in …

Jun 1, 2026
CVE-2026-10235
6.3 MEDIUM

A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the …

Jun 1, 2026
CVE-2026-10232
5.3 MEDIUM

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component …

Jun 1, 2026
CVE-2026-10231
5.3 MEDIUM

A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of the file HL1MDLLoader.cpp of the component Half-Life 1 …

Jun 1, 2026
CVE-2026-10230
5.3 MEDIUM

A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. …

Jun 1, 2026
CVE-2026-10229
5.3 MEDIUM

A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. …

Jun 1, 2026
CVE-2026-10224
5.3 MEDIUM

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component …

Jun 1, 2026
CVE-2026-10223
6.3 MEDIUM

A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The …

Jun 1, 2026
CVE-2026-10222
5.6 MEDIUM

A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The …

Jun 1, 2026
CVE-2026-48208
6.5 MEDIUM

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via …

Jun 1, 2026
CVE-2026-48189
5.7 MEDIUM

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the …

Jun 1, 2026
CVE-2026-48187
5.7 MEDIUM

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of …

Jun 1, 2026
CVE-2026-20456
5.5 MEDIUM

In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with …

Jun 1, 2026
CVE-2026-20454
6.4 MEDIUM

In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a …

Jun 1, 2026
CVE-2026-20453
6.7 MEDIUM

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Jun 1, 2026
CVE-2026-10218
5.4 MEDIUM

A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper …

Jun 1, 2026
CVE-2026-10217
6.3 MEDIUM

A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component …

Jun 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.