CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13589
5.6 MEDIUM

A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand of the file Packet++/src/TelnetLayer.cpp of the component Telnet Subnegotiation Packet Handler. The …

Jun 29, 2026
CVE-2026-13588
5.6 MEDIUM

A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMessage::getHandshakeVersion of the file Packet++/src/SSLHandshake.cpp of the component TLS Hello Handler. …

Jun 29, 2026
CVE-2026-12912
7.3 HIGH

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when …

Jun 29, 2026
CVE-2026-9105
6.5 MEDIUM

An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests …

Jun 29, 2026
CVE-2026-41052
8.8 HIGH

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and …

Jun 29, 2026
CVE-2026-13750
5.5 MEDIUM

Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. …

Jun 29, 2026
CVE-2026-13749
8.8 HIGH

Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling or deployment. …

Jun 29, 2026
CVE-2026-13748
6.3 MEDIUM

Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake …

Jun 29, 2026
CVE-2026-13746
3.6 LOW

Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying …

Jun 29, 2026
CVE-2026-13744
8.3 HIGH

Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project configuration, manifest data, …

Jun 29, 2026
CVE-2026-13742

Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, …

Jun 29, 2026
CVE-2026-13587
3.7 LOW

A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the file light_pcapng.c of the component LightPcapNg Parser. Performing …

Jun 29, 2026
CVE-2026-13583
8.8 HIGH

A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such …

Jun 29, 2026
CVE-2026-13582
8.8 HIGH

A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. …

Jun 29, 2026
CVE-2026-13581
6.3 MEDIUM

A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The …

Jun 29, 2026
CVE-2026-13580
8.8 HIGH

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. …

Jun 29, 2026
CVE-2026-13437
6.5 MEDIUM

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent …

Jun 29, 2026
CVE-2026-57525

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 29, 2026
CVE-2026-57523

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 29, 2026
CVE-2026-57341
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.

Jun 29, 2026
CVE-2026-57340
6.5 MEDIUM

Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

Jun 29, 2026
CVE-2026-57339
6.5 MEDIUM

Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

Jun 29, 2026
CVE-2026-57338
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.

Jun 29, 2026
CVE-2026-57337
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.

Jun 29, 2026
CVE-2026-57336
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.

Jun 29, 2026
CVE-2026-57335
6.5 MEDIUM

Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

Jun 29, 2026
CVE-2026-57334
6.5 MEDIUM

Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

Jun 29, 2026
CVE-2026-57333
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

Jun 29, 2026
CVE-2026-57332
7.1 HIGH

Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

Jun 29, 2026
CVE-2026-57331
9.9 CRITICAL

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

Jun 29, 2026
CVE-2026-57330
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.

Jun 29, 2026
CVE-2026-57329
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.

Jun 29, 2026
CVE-2026-57328
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

Jun 29, 2026
CVE-2026-57327
6.3 MEDIUM

Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

Jun 29, 2026
CVE-2026-57326
6.1 MEDIUM

Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

Jun 29, 2026
CVE-2026-57320
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.

Jun 29, 2026
CVE-2026-56290
9.8 CRITICAL KEV

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jun 29, 2026
CVE-2026-56124
7.5 HIGH

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting …

Jun 29, 2026
CVE-2026-55844
7.5 HIGH

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID …

Jun 29, 2026
CVE-2026-55607
8.8 HIGH

Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees …

Jun 29, 2026
CVE-2026-49049
7.5 HIGH

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template …

Jun 29, 2026
CVE-2026-46406
6.1 MEDIUM

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without …

Jun 29, 2026
CVE-2026-13579
6.3 MEDIUM

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a …

Jun 29, 2026
CVE-2026-13578
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing …

Jun 29, 2026
CVE-2026-13574
3.3 LOW

A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. …

Jun 29, 2026
CVE-2026-13573
3.3 LOW

A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The …

Jun 29, 2026
CVE-2026-13572
6.3 MEDIUM

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation of …

Jun 29, 2026
CVE-2026-13571
5.3 MEDIUM

A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a …

Jun 29, 2026
CVE-2026-56457
4.3 MEDIUM

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with …

Jun 29, 2026
CVE-2026-54371
7.1 HIGH

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a …

Jun 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.