CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-36770
7.5 HIGH

Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered to contain a stack overflow in the Go parameter of the ask_to_reboot function. This vulnerability …

Jun 9, 2026
CVE-2026-36723
8.8 HIGH

An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from …

Jun 9, 2026
CVE-2026-36720
8.1 HIGH

Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.

Jun 9, 2026
CVE-2026-36719
7.5 HIGH

An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via enumerating user …

Jun 9, 2026
CVE-2025-55657
7.5 HIGH

A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 9, 2026
CVE-2025-52293
7.5 HIGH

A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC …

Jun 9, 2026
CVE-2025-52292
7.5 HIGH

A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 9, 2026
CVE-2023-43688
7.5 HIGH

An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities.

Jun 9, 2026
CVE-2023-29146
8.2 HIGH

The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds …

Jun 9, 2026
CVE-2026-50636
8.8 HIGH

The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values directly into a tid IN ('...') SQL …

Jun 9, 2026
CVE-2026-50635
8.8 HIGH

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in …

Jun 9, 2026
CVE-2026-50512
7.8 HIGH

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-50511
7.8 HIGH

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-48293
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 9, 2026
CVE-2026-34708
7.8 HIGH

InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Jun 9, 2026
CVE-2026-34707
7.8 HIGH

InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Jun 9, 2026
CVE-2026-34706
7.8 HIGH

InCopy versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Jun 9, 2026
CVE-2026-34702
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 9, 2026
CVE-2026-34701
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 9, 2026
CVE-2026-34700
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 9, 2026
CVE-2026-34699
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 9, 2026
CVE-2026-34698
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 9, 2026
CVE-2026-34697
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 9, 2026
CVE-2026-34696
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Jun 9, 2026
CVE-2026-34695
7.8 HIGH

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 9, 2026
CVE-2026-34693
8.0 HIGH

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this …

Jun 9, 2026
CVE-2026-9076
7.5 HIGH

Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap …

Jun 9, 2026
CVE-2026-7383
8.1 HIGH

Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: …

Jun 9, 2026
CVE-2026-49959
8.8 HIGH

Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration …

Jun 9, 2026
CVE-2026-49957
7.7 HIGH

Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attackers to circumvent blocked-root path checks by exploiting an early return …

Jun 9, 2026
CVE-2026-49847
7.5 HIGH

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. …

Jun 9, 2026
CVE-2026-49842
7.5 HIGH

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. …

Jun 9, 2026
CVE-2026-49475
7.5 HIGH

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. …

Jun 9, 2026
CVE-2026-49161
7.8 HIGH

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-49160
7.5 HIGH

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

Jun 9, 2026
CVE-2026-48583
7.8 HIGH

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-48578
7.9 HIGH

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-48576
7.9 HIGH

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-48575
7.9 HIGH

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-48574
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Jun 9, 2026
CVE-2026-48573
7.9 HIGH

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-48570
7.9 HIGH

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-48569
7.1 HIGH

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-48568
7.9 HIGH

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-48565
7.8 HIGH

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Jun 9, 2026
CVE-2026-48563
7.5 HIGH

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-47656
7.9 HIGH

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

Jun 9, 2026
CVE-2026-47654
7.5 HIGH

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-47653
8.8 HIGH

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-47652
8.2 HIGH

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Jun 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.