CVE Database

54056+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10274
6.3 MEDIUM

A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAssetMetadata of the file src/mcp-server.ts of the component Axios Request Flow. …

Jun 1, 2026
CVE-2026-10272
6.5 MEDIUM

A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of …

Jun 1, 2026
CVE-2026-10271
6.3 MEDIUM

A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the component …

Jun 1, 2026
CVE-2026-10269
6.3 MEDIUM

A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component …

Jun 1, 2026
CVE-2026-48559
5.4 MEDIUM

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media …

Jun 1, 2026
CVE-2026-10533
5.0 MEDIUM

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not …

Jun 1, 2026
CVE-2026-10265
6.3 MEDIUM

A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of …

Jun 1, 2026
CVE-2025-60495
5.5 MEDIUM

A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 1, 2026
CVE-2025-60486
5.5 MEDIUM

A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 1, 2026
CVE-2025-60485
5.5 MEDIUM

A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 1, 2026
CVE-2025-60483
5.5 MEDIUM

A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Jun 1, 2026
CVE-2025-60481
5.5 MEDIUM

A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Jun 1, 2026
CVE-2025-55664
5.5 MEDIUM

A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a …

Jun 1, 2026
CVE-2026-9309
5.4 MEDIUM

Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior …

Jun 1, 2026
CVE-2026-9308
5.4 MEDIUM

Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string …

Jun 1, 2026
CVE-2026-34193
4.3 MEDIUM

Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the …

Jun 1, 2026
CVE-2026-10258
6.3 MEDIUM

A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument …

Jun 1, 2026
CVE-2026-10257
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of …

Jun 1, 2026
CVE-2026-10256
6.3 MEDIUM

A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name …

Jun 1, 2026
CVE-2026-10255
5.3 MEDIUM

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. …

Jun 1, 2026
CVE-2026-10254
5.3 MEDIUM

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file …

Jun 1, 2026
CVE-2026-49328
5.3 MEDIUM

Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or …

Jun 1, 2026
CVE-2026-25600
6.4 MEDIUM

The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the …

Jun 1, 2026
CVE-2026-25599
6.3 MEDIUM

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, …

Jun 1, 2026
CVE-2026-10248
4.7 MEDIUM

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of …

Jun 1, 2026
CVE-2026-8474
5.3 MEDIUM

A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute …

Jun 1, 2026
CVE-2026-49270
5.9 MEDIUM

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with …

Jun 1, 2026
CVE-2026-49267
5.9 MEDIUM

Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] …

Jun 1, 2026
CVE-2026-48726
6.5 MEDIUM

A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow …

Jun 1, 2026
CVE-2026-46764
4.3 MEDIUM

The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, …

Jun 1, 2026
CVE-2026-46605
4.3 MEDIUM

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache …

Jun 1, 2026
CVE-2026-42360
6.5 MEDIUM

A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON …

Jun 1, 2026
CVE-2026-42358
6.5 MEDIUM

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when …

Jun 1, 2026
CVE-2026-42253
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API …

Jun 1, 2026
CVE-2026-41017
5.9 MEDIUM

Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. …

Jun 1, 2026
CVE-2026-41014
4.3 MEDIUM

The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate …

Jun 1, 2026
CVE-2026-40861
6.5 MEDIUM

A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process …

Jun 1, 2026
CVE-2026-10517
5.8 MEDIUM

A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. …

Jun 1, 2026
CVE-2026-10242
6.3 MEDIUM

A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument …

Jun 1, 2026
CVE-2026-10241
6.3 MEDIUM

A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug …

Jun 1, 2026
CVE-2026-10240
6.3 MEDIUM

A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument …

Jun 1, 2026
CVE-2026-10239
6.3 MEDIUM

A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead …

Jun 1, 2026
CVE-2026-10237
4.7 MEDIUM

A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user of the component User Management …

Jun 1, 2026
CVE-2026-45192
6.5 MEDIUM

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in …

Jun 1, 2026
CVE-2026-10235
6.3 MEDIUM

A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the …

Jun 1, 2026
CVE-2026-10232
5.3 MEDIUM

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component …

Jun 1, 2026
CVE-2026-10231
5.3 MEDIUM

A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of the file HL1MDLLoader.cpp of the component Half-Life 1 …

Jun 1, 2026
CVE-2026-10230
5.3 MEDIUM

A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. …

Jun 1, 2026
CVE-2026-10229
5.3 MEDIUM

A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. …

Jun 1, 2026
CVE-2026-10224
5.3 MEDIUM

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component …

Jun 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.