CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10045
9.8 CRITICAL

Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and …

Jun 9, 2026
CVE-2026-34691
9.3 CRITICAL

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by …

Jun 9, 2026
CVE-2026-49841
9.8 CRITICAL

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. …

Jun 9, 2026
CVE-2026-49840
9.1 CRITICAL

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. …

Jun 9, 2026
CVE-2026-47643
9.8 CRITICAL

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-47291
9.8 CRITICAL

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-47281
9.6 CRITICAL

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Jun 9, 2026
CVE-2026-45657
9.8 CRITICAL

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-45602
9.1 CRITICAL

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

Jun 9, 2026
CVE-2026-44815
9.8 CRITICAL

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-42904
9.6 CRITICAL

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

Jun 9, 2026
CVE-2026-38615
9.8 CRITICAL

DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

Jun 9, 2026
CVE-2026-34182
9.1 CRITICAL

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to …

Jun 9, 2026
CVE-2026-26142
9.8 CRITICAL

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

Jun 9, 2026
CVE-2026-8025
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue …

Jun 9, 2026
CVE-2026-25089
9.8 CRITICAL KEV

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, …

Jun 9, 2026
CVE-2026-10523
9.9 CRITICAL

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts …

Jun 9, 2026
CVE-2026-10520
10.0 CRITICAL KEV

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code …

Jun 9, 2026
CVE-2026-7486
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection. This issue affects E-İmar: …

Jun 9, 2026
CVE-2026-46325
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles …

Jun 9, 2026
CVE-2026-46316
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks …

Jun 9, 2026
CVE-2017-20251
9.8 CRITICAL

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious …

Jun 9, 2026
CVE-2025-10263
9.1 CRITICAL

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, …

Jun 9, 2026
CVE-2009-10007
9.1 CRITICAL

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that …

Jun 9, 2026
CVE-2026-9698
9.8 CRITICAL

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were …

Jun 9, 2026
CVE-2026-44083
9.8 CRITICAL

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. …

Jun 9, 2026
CVE-2026-5067
9.8 CRITICAL

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser …

Jun 9, 2026
CVE-2026-44748
9.9 CRITICAL

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed …

Jun 9, 2026
CVE-2026-40128
9.0 CRITICAL

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path …

Jun 9, 2026
CVE-2026-27671
9.8 CRITICAL

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker …

Jun 9, 2026
CVE-2026-11697
9.6 CRITICAL

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 9, 2026
CVE-2026-11671
9.6 CRITICAL

Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jun 9, 2026
CVE-2026-11659
9.6 CRITICAL

Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jun 9, 2026
CVE-2026-11654
9.6 CRITICAL

Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 9, 2026
CVE-2026-11651
9.6 CRITICAL

Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jun 9, 2026
CVE-2026-11638
9.6 CRITICAL

Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jun 9, 2026
CVE-2026-11634
9.6 CRITICAL

Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a …

Jun 9, 2026
CVE-2026-52778
9.8 CRITICAL

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of …

Jun 8, 2026
CVE-2026-11393
9.0 CRITICAL

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code …

Jun 8, 2026
CVE-2026-46289
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. Fix bugs …

Jun 8, 2026
CVE-2026-41448
9.4 CRITICAL

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a …

Jun 8, 2026
CVE-2026-39910
9.8 CRITICAL

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service …

Jun 8, 2026
CVE-2026-25555
9.8 CRITICAL

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying …

Jun 8, 2026
CVE-2026-46442
9.9 CRITICAL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, …

Jun 8, 2026
CVE-2026-46441
9.6 CRITICAL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists …

Jun 8, 2026
CVE-2026-46440
9.1 CRITICAL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials …

Jun 8, 2026
CVE-2026-44631
9.8 CRITICAL

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users …

Jun 8, 2026
CVE-2026-42861
9.6 CRITICAL

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists …

Jun 8, 2026
CVE-2026-42535
9.1 CRITICAL

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing …

Jun 8, 2026
CVE-2026-29167
9.8 CRITICAL

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are …

Jun 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.