CVE Vulnerability Database
Search and browse 390,364 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53692 | MEDIUM | 5.9 | — | Jun 30, 2026 | Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographical... |
| CVE-2026-53691 | HIGH | 8.6 | — | Jun 30, 2026 | An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote C... |
| CVE-2026-53690 | CRITICAL | 9.3 | — | Jun 30, 2026 | An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/inde... |
| CVE-2026-41053 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused ... |
| CVE-2026-14162 | CRITICAL | 9.8 | — | Jun 30, 2026 | Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated... |
| CVE-2026-14161 | HIGH | 8.7 | — | Jun 30, 2026 | Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated... |
| CVE-2026-13766 | CRITICAL | 9.8 | — | Jun 30, 2026 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL buil... |
| CVE-2026-54475 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Cl... |
| CVE-2026-53917 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Clien... |
| CVE-2026-53916 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp... |
| CVE-2026-52760 | MEDIUM | 6.1 | 0.3% | Jun 30, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A... |
| CVE-2026-50750 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Foll... |
| CVE-2026-50734 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ Al... |
| CVE-2026-49877 | HIGH | 8.1 | 0.4% | Jun 30, 2026 | Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can... |
| CVE-2026-49434 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker th... |
| CVE-2026-49432 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauth... |
| CVE-2026-13316 | MEDIUM | 4.4 | 0.1% | Jun 30, 2026 | A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Atta... |
| CVE-2026-9711 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the... |
| CVE-2026-8141 | HIGH | 7.2 | 0.3% | Jun 30, 2026 | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include... |
| CVE-2026-6954 | MEDIUM | 5.1 | 0.4% | Jun 30, 2026 | Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to... |
| CVE-2026-6953 | MEDIUM | 5.1 | 0.4% | Jun 30, 2026 | HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an ema... |
| CVE-2026-13149 | HIGH | 7.7 | 0.4% | Jun 30, 2026 | brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time comple... |
| CVE-2026-12610 | MEDIUM | 6.4 | 0.1% | Jun 30, 2026 | A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free v... |
| CVE-2026-12076 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote, ... |
| CVE-2026-10763 | HIGH | 7 | 0.3% | Jun 30, 2026 | PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support fr... |
