CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13780
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially …

Jun 30, 2026
CVE-2026-13776
9.8 CRITICAL

Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jun 30, 2026
CVE-2026-13775
9.8 CRITICAL

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a …

Jun 30, 2026
CVE-2026-58449
9.8 CRITICAL

txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr …

Jun 30, 2026
CVE-2026-50003
9.8 CRITICAL

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative …

Jun 30, 2026
CVE-2026-37106
9.8 CRITICAL

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed …

Jun 30, 2026
CVE-2026-7874
9.1 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation …

Jun 30, 2026
CVE-2026-7873
9.9 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and …

Jun 30, 2026
CVE-2026-7871
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system …

Jun 30, 2026
CVE-2026-7803
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.

Jun 30, 2026
CVE-2026-7663
9.1 CRITICAL

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement …

Jun 30, 2026
CVE-2026-11712
9.3 CRITICAL

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

Jun 30, 2026
CVE-2026-11708
9.3 CRITICAL

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.

Jun 30, 2026
CVE-2026-10140
9.6 CRITICAL

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can …

Jun 30, 2026
CVE-2026-10134
10.0 CRITICAL

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, …

Jun 30, 2026
CVE-2026-10109
9.8 CRITICAL

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Jun 30, 2026
CVE-2026-58138
9.8 CRITICAL

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow …

Jun 30, 2026
CVE-2026-58172
9.1 CRITICAL

Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket …

Jun 30, 2026
CVE-2026-58166
9.1 CRITICAL

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write or delete arbitrary files by …

Jun 30, 2026
CVE-2026-48315
9.3 CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of …

Jun 30, 2026
CVE-2026-48313
9.3 CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead …

Jun 30, 2026
CVE-2026-48286
10.0 CRITICAL

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in …

Jun 30, 2026
CVE-2026-48283
10.0 CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution …

Jun 30, 2026
CVE-2026-48282
10.0 CRITICAL KEV

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead …

Jun 30, 2026
CVE-2026-48281
10.0 CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of …

Jun 30, 2026
CVE-2026-48277
10.0 CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of …

Jun 30, 2026
CVE-2026-48276
10.0 CRITICAL

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution …

Jun 30, 2026
CVE-2026-14241
9.8 CRITICAL

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Jun 30, 2026
CVE-2026-8655
9.8 CRITICAL

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured …

Jun 30, 2026
CVE-2026-8452
9.8 CRITICAL

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a …

Jun 30, 2026
CVE-2026-6556
9.1 CRITICAL

@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays …

Jun 30, 2026
CVE-2026-58116
9.8 CRITICAL

LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model …

Jun 30, 2026
CVE-2026-8402
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows …

Jun 30, 2026
CVE-2026-14162
9.8 CRITICAL

Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.

Jun 30, 2026
CVE-2026-13766
9.8 CRITICAL

DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor …

Jun 30, 2026
CVE-2026-9711
9.8 CRITICAL

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up …

Jun 30, 2026
CVE-2026-12073
9.8 CRITICAL

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Jun 30, 2026
CVE-2026-55276
9.1 CRITICAL

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. …

Jun 29, 2026
CVE-2026-53434
9.1 CRITICAL

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 …

Jun 29, 2026
CVE-2026-57498
9.6 CRITICAL

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) …

Jun 29, 2026
CVE-2026-39868
9.1 CRITICAL

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be …

Jun 29, 2026
CVE-2026-37637
9.1 CRITICAL

An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component

Jun 29, 2026
CVE-2026-13763
9.8 CRITICAL

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body …

Jun 29, 2026
CVE-2026-13762
9.8 CRITICAL

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via …

Jun 29, 2026
CVE-2026-56782
9.8 CRITICAL

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is …

Jun 29, 2026
CVE-2026-11720
9.1 CRITICAL

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into …

Jun 29, 2026
CVE-2026-57331
9.9 CRITICAL

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

Jun 29, 2026
CVE-2026-56290
9.8 CRITICAL KEV

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jun 29, 2026
CVE-2026-49048
9.8 CRITICAL

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string …

Jun 28, 2026
CVE-2026-58053
9.9 CRITICAL

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: …

Jun 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.