CVE Vulnerability Database
Search and browse 394,243 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10646 | HIGH | 7.4 | 0.3% | Jun 28, 2026 | Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-all... |
| CVE-2026-10644 | LOW | 3.1 | 0.1% | Jun 28, 2026 | The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains ... |
| CVE-2026-10593 | MEDIUM | 6.5 | 0.2% | Jun 28, 2026 | The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications.... |
| CVE-2026-58058 | MEDIUM | 6.9 | 0.3% | Jun 28, 2026 | Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (li... |
| CVE-2026-58057 | MEDIUM | 5 | 0.2% | Jun 28, 2026 | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparis... |
| CVE-2026-58056 | HIGH | 7.6 | 0.2% | Jun 28, 2026 | RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type... |
| CVE-2026-58055 | MEDIUM | 6.3 | 0.2% | Jun 28, 2026 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an... |
| CVE-2026-58054 | — | — | 0.3% | Jun 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE was assigned on the... |
| CVE-2026-58053 | CRITICAL | 9.9 | 0.3% | Jun 28, 2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke... |
| CVE-2026-58052 | MEDIUM | 4.8 | 0.1% | Jun 28, 2026 | 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because it... |
| CVE-2026-58051 | HIGH | 8.3 | 0.3% | Jun 28, 2026 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsin... |
| CVE-2026-58050 | HIGH | 7.5 | 0.3% | Jun 28, 2026 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses ... |
| CVE-2026-58049 | HIGH | 8.6 | 0.3% | Jun 28, 2026 | FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before... |
| CVE-2026-8095 | HIGH | 8.1 | 0.4% | Jun 28, 2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions... |
| CVE-2026-10643 | HIGH | 7.8 | 0.1% | Jun 28, 2026 | Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user... |
| CVE-2026-49416 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer ... |
| CVE-2026-49414 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the P... |
| CVE-2026-49417 | HIGH | 7 | 0.1% | Jun 27, 2026 | Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va... |
| CVE-2026-49413 | HIGH | 7.1 | 0.1% | Jun 27, 2026 | The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin... |
| CVE-2026-49412 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, ... |
| CVE-2026-45259 | MEDIUM | 6.5 | 0.1% | Jun 27, 2026 | sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation... |
| CVE-2026-45258 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the... |
| CVE-2026-9242 | MEDIUM | 5.3 | 0.2% | Jun 27, 2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
| CVE-2026-9233 | MEDIUM | 4.3 | 0.3% | Jun 27, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass... |
| CVE-2026-3462 | MEDIUM | 6.5 | 0.3% | Jun 27, 2026 | The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks... |
