CVE Vulnerability Database
Search and browse 392,327 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36372 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2026-58138 | CRITICAL | 9.8 | 0.9% | Jun 30, 2026 | Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote... |
| CVE-2026-10513 | HIGH | 7.2 | 0.2% | Jun 30, 2026 | The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 v... |
| CVE-2026-9263 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the l... |
| CVE-2026-8864 | HIGH | 7.3 | 0.1% | Jun 30, 2026 | The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been rel... |
| CVE-2026-58377 | HIGH | 8.6 | 0.3% | Jun 30, 2026 | JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to ... |
| CVE-2026-58376 | HIGH | 7.6 | 0.2% | Jun 30, 2026 | Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API u... |
| CVE-2026-58375 | HIGH | 8.7 | 0.5% | Jun 30, 2026 | JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotate... |
| CVE-2026-58373 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows aut... |
| CVE-2026-58372 | HIGH | 8.1 | 0.8% | Jun 30, 2026 | SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows... |
| CVE-2026-58371 | LOW | 3.1 | 0.2% | Jun 30, 2026 | SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application... |
| CVE-2026-58370 | CRITICAL | 9.2 | 0.5% | Jun 30, 2026 | Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driv... |
| CVE-2026-58369 | MEDIUM | 6.9 | 0.4% | Jun 30, 2026 | Woodpecker before 3.15.0 registers the /api/orgs/lookup/*org_full_name endpoint without authentication middleware, and t... |
| CVE-2026-58176 | HIGH | 7.1 | 0.3% | Jun 30, 2026 | RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (... |
| CVE-2026-58174 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but construct... |
| CVE-2026-58173 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the inte... |
| CVE-2026-58172 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie... |
| CVE-2026-58171 | MEDIUM | 4.2 | 0.3% | Jun 30, 2026 | Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs ... |
| CVE-2026-58170 | HIGH | 8.3 | 0.4% | Jun 30, 2026 | Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broke... |
| CVE-2026-58169 | HIGH | 7.7 | 0.3% | Jun 30, 2026 | Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to ... |
| CVE-2026-58168 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke... |
| CVE-2026-58167 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT... |
| CVE-2026-58166 | CRITICAL | 9.1 | 0.6% | Jun 30, 2026 | OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica... |
| CVE-2026-58165 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated... |
| CVE-2026-49451 | HIGH | 7.5 | 0.7% | Jun 30, 2026 | The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extrac... |
