CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10297
6.3 MEDIUM

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID …

Jun 1, 2026
CVE-2026-10296
6.3 MEDIUM

A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation …

Jun 1, 2026
CVE-2025-59614
6.7 MEDIUM

Memory Corruption when sending random number generator command with insufficient output buffer size.

Jun 1, 2026
CVE-2025-59613
6.7 MEDIUM

Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.

Jun 1, 2026
CVE-2025-59612
6.7 MEDIUM

Memory corruption in windows drivers while sending incorrect trusted application request

Jun 1, 2026
CVE-2025-59611
6.7 MEDIUM

Memory corruption in diagnostic services due to absence of input validation

Jun 1, 2026
CVE-2025-59610
6.4 MEDIUM

Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.

Jun 1, 2026
CVE-2025-59609
5.5 MEDIUM

Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.

Jun 1, 2026
CVE-2025-59601
6.5 MEDIUM

Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.

Jun 1, 2026
CVE-2026-28581
4.0 MEDIUM

In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead …

Jun 1, 2026
CVE-2026-28578
5.5 MEDIUM

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service …

Jun 1, 2026
CVE-2026-10294
4.3 MEDIUM

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation …

Jun 1, 2026
CVE-2026-10291
4.3 MEDIUM

A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the …

Jun 1, 2026
CVE-2026-0086
6.8 MEDIUM

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation …

Jun 1, 2026
CVE-2026-0085
5.5 MEDIUM

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local …

Jun 1, 2026
CVE-2026-0080
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial …

Jun 1, 2026
CVE-2026-0079
5.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of …

Jun 1, 2026
CVE-2026-0075
5.9 MEDIUM

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of …

Jun 1, 2026
CVE-2026-0074
5.5 MEDIUM

In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no …

Jun 1, 2026
CVE-2026-0070
5.5 MEDIUM

In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to …

Jun 1, 2026
CVE-2026-0069
5.5 MEDIUM

In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service …

Jun 1, 2026
CVE-2026-0067
5.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. …

Jun 1, 2026
CVE-2026-0061
5.9 MEDIUM

In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could …

Jun 1, 2026
CVE-2026-0060
5.5 MEDIUM

In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service …

Jun 1, 2026
CVE-2026-0055
6.2 MEDIUM

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. …

Jun 1, 2026
CVE-2026-0052
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial …

Jun 1, 2026
CVE-2026-0051
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remote …

Jun 1, 2026
CVE-2026-0048
6.8 MEDIUM

In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to …

Jun 1, 2026
CVE-2026-0046
6.2 MEDIUM

In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead …

Jun 1, 2026
CVE-2026-0044
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to …

Jun 1, 2026
CVE-2026-0043
5.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of …

Jun 1, 2026
CVE-2026-0042
5.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service …

Jun 1, 2026
CVE-2026-0041
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service with …

Jun 1, 2026
CVE-2026-0040
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial …

Jun 1, 2026
CVE-2026-0039
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of …

Jun 1, 2026
CVE-2026-0018
5.5 MEDIUM

In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of …

Jun 1, 2026
CVE-2025-48648
5.5 MEDIUM

In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional …

Jun 1, 2026
CVE-2019-25716
6.5 MEDIUM

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending …

Jun 1, 2026
CVE-2018-25435
5.3 MEDIUM

ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can …

Jun 1, 2026
CVE-2026-49433
5.0 MEDIUM

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the …

Jun 1, 2026
CVE-2026-49140
4.3 MEDIUM

Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust …

Jun 1, 2026
CVE-2026-49138
5.0 MEDIUM

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network …

Jun 1, 2026
CVE-2026-10289
4.3 MEDIUM

A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a …

Jun 1, 2026
CVE-2026-10286
6.3 MEDIUM

A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results …

Jun 1, 2026
CVE-2026-10285
5.4 MEDIUM

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the …

Jun 1, 2026
CVE-2026-10284
5.4 MEDIUM

A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the …

Jun 1, 2026
CVE-2026-45810
6.8 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check …

Jun 1, 2026
CVE-2026-45729
4.3 MEDIUM

Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes …

Jun 1, 2026
CVE-2026-45691
5.9 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session …

Jun 1, 2026
CVE-2026-45690
5.9 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass …

Jun 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.