CVE Vulnerability Database
Search and browse 390,334 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58170 | HIGH | 8.3 | 0.4% | Jun 30, 2026 | Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broke... |
| CVE-2026-58169 | HIGH | 7.7 | 0.3% | Jun 30, 2026 | Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to ... |
| CVE-2026-58168 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke... |
| CVE-2026-58167 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT... |
| CVE-2026-58166 | CRITICAL | 9.1 | 0.6% | Jun 30, 2026 | OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica... |
| CVE-2026-58165 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated... |
| CVE-2026-49451 | HIGH | 7.5 | 0.7% | Jun 30, 2026 | The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extrac... |
| CVE-2026-10655 | MEDIUM | 5.9 | 0.3% | Jun 30, 2026 | The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket file descrip... |
| CVE-2026-10654 | LOW | 3.1 | 0.1% | Jun 30, 2026 | A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a... |
| CVE-2026-10653 | HIGH | 8.1 | 0.3% | Jun 30, 2026 | The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and t... |
| CVE-2026-10652 | HIGH | 7.4 | 0.3% | Jun 30, 2026 | Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which vali... |
| CVE-2026-48315 | CRITICAL | 9.3 | 1.0% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-48314 | MEDIUM | 6.5 | 0.6% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir... |
| CVE-2026-48313 | CRITICAL | 9.3 | 3.0% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir... |
| CVE-2026-48307 | HIGH | 8.8 | 0.5% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An... |
| CVE-2026-48286 | CRITICAL | 10 | 1.2% | Jun 30, 2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerabil... |
| CVE-2026-48285 | HIGH | 8.6 | 0.8% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that ... |
| CVE-2026-48283 | CRITICAL | 10 | 1.3% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne... |
| CVE-2026-48282 | CRITICAL | 10 | 42.4% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir... |
| CVE-2026-48281 | CRITICAL | 10 | 1.4% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-48277 | CRITICAL | 10 | 1.3% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-48276 | CRITICAL | 10 | 1.3% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne... |
| CVE-2026-44948 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up... |
| CVE-2026-13455 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ... |
| CVE-2026-4360 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy... |
