CVE Database

54056+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-0044
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to …

Jun 1, 2026
CVE-2026-0043
5.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of …

Jun 1, 2026
CVE-2026-0042
5.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service …

Jun 1, 2026
CVE-2026-0041
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service with …

Jun 1, 2026
CVE-2026-0040
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial …

Jun 1, 2026
CVE-2026-0039
6.5 MEDIUM

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of …

Jun 1, 2026
CVE-2026-0018
5.5 MEDIUM

In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of …

Jun 1, 2026
CVE-2025-48648
5.5 MEDIUM

In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional …

Jun 1, 2026
CVE-2019-25716
6.5 MEDIUM

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending …

Jun 1, 2026
CVE-2018-25435
5.3 MEDIUM

ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can …

Jun 1, 2026
CVE-2026-49433
5.0 MEDIUM

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the …

Jun 1, 2026
CVE-2026-49140
4.3 MEDIUM

Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust …

Jun 1, 2026
CVE-2026-49138
5.0 MEDIUM

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network …

Jun 1, 2026
CVE-2026-10289
4.3 MEDIUM

A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a …

Jun 1, 2026
CVE-2026-10286
6.3 MEDIUM

A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results …

Jun 1, 2026
CVE-2026-10285
5.4 MEDIUM

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the …

Jun 1, 2026
CVE-2026-10284
5.4 MEDIUM

A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the …

Jun 1, 2026
CVE-2026-45810
6.8 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check …

Jun 1, 2026
CVE-2026-45729
4.3 MEDIUM

Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes …

Jun 1, 2026
CVE-2026-45691
5.9 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session …

Jun 1, 2026
CVE-2026-45690
5.9 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass …

Jun 1, 2026
CVE-2026-45544
4.3 MEDIUM

Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only …

Jun 1, 2026
CVE-2026-45543
5.3 MEDIUM

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent …

Jun 1, 2026
CVE-2026-45286
4.3 MEDIUM

Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users …

Jun 1, 2026
CVE-2026-45285
6.4 MEDIUM

Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder …

Jun 1, 2026
CVE-2026-45284
4.6 MEDIUM

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP …

Jun 1, 2026
CVE-2026-45283
6.3 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app …

Jun 1, 2026
CVE-2026-45282
6.5 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker …

Jun 1, 2026
CVE-2026-45279
4.4 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is …

Jun 1, 2026
CVE-2026-45275
6.5 MEDIUM

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user …

Jun 1, 2026
CVE-2026-43625
5.9 MEDIUM

CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling …

Jun 1, 2026
CVE-2026-40990
5.7 MEDIUM

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions …

Jun 1, 2026
CVE-2026-40989
5.7 MEDIUM

Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 …

Jun 1, 2026
CVE-2026-23638
6.5 MEDIUM

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an …

Jun 1, 2026
CVE-2026-10283
6.3 MEDIUM

A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setting Handler. Performing a manipulation results in …

Jun 1, 2026
CVE-2026-10282
4.3 MEDIUM

A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manipulation leads to …

Jun 1, 2026
CVE-2026-10279
6.3 MEDIUM

A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/write_to_specific_pane. The manipulation …

Jun 1, 2026
CVE-2026-10278
6.3 MEDIUM

A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a …

Jun 1, 2026
CVE-2026-10277
6.3 MEDIUM

A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail …

Jun 1, 2026
CVE-2026-10276
6.3 MEDIUM

A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get_build_status/get_build_log/trigger_build. Such manipulation …

Jun 1, 2026
CVE-2026-8643
5.5 MEDIUM

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry …

Jun 1, 2026
CVE-2026-45267
6.5 MEDIUM

Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other …

Jun 1, 2026
CVE-2026-45264
4.3 MEDIUM

Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before …

Jun 1, 2026
CVE-2026-45157
6.3 MEDIUM

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious …

Jun 1, 2026
CVE-2026-45153
4.6 MEDIUM

Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be …

Jun 1, 2026
CVE-2026-44740
6.5 MEDIUM

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in …

Jun 1, 2026
CVE-2026-42679
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: …

Jun 1, 2026
CVE-2026-42676
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

Jun 1, 2026
CVE-2026-42671
6.5 MEDIUM

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

Jun 1, 2026
CVE-2026-10275
5.0 MEDIUM

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation …

Jun 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.