CVE Vulnerability Database
Search and browse 392,387 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51219 | HIGH | 7.5 | 0.3% | Jun 29, 2026 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows... |
| CVE-2026-51218 | HIGH | 7.5 | 0.3% | Jun 29, 2026 | A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows at... |
| CVE-2026-10648 | MEDIUM | 5.5 | 0.1% | Jun 29, 2026 | mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm... |
| CVE-2026-57997 | MEDIUM | 5.4 | 0.1% | Jun 29, 2026 | Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not exp... |
| CVE-2026-51221 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D... |
| CVE-2026-34592 | HIGH | 7.7 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-10647 | MEDIUM | 5.3 | 0.2% | Jun 29, 2026 | The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue()... |
| CVE-2026-55957 | HIGH | 7.3 | 0.3% | Jun 29, 2026 | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate... |
| CVE-2026-55956 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ig... |
| CVE-2026-55955 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ... |
| CVE-2026-55276 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa... |
| CVE-2026-53434 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect... |
| CVE-2026-53404 | HIGH | 7.3 | 0.2% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond... |
| CVE-2026-50229 | MEDIUM | 6.1 | 0.2% | Jun 29, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ... |
| CVE-2026-41896 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34597 | HIGH | 8.8 | 0.5% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34594 | HIGH | 8.8 | 1.1% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-13758 | LOW | 3.7 | 0.2% | Jun 29, 2026 | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt... |
| CVE-2026-57919 | HIGH | 7.8 | 0.1% | Jun 29, 2026 | PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA... |
| CVE-2026-57498 | CRITICAL | 9.6 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-56018 | HIGH | 7.5 | 0.6% | Jun 29, 2026 | JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory ... |
| CVE-2026-56017 | HIGH | 7.5 | 0.5% | Jun 29, 2026 | JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful t... |
| CVE-2026-54889 | MEDIUM | 5.1 | 0.3% | Jun 29, 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri... |
| CVE-2026-54888 | MEDIUM | 6.9 | 0.2% | Jun 29, 2026 | Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex ... |
| CVE-2026-53429 | MEDIUM | 6.9 | 0.1% | Jun 29, 2026 | Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh... |
