CVE Vulnerability Database
Search and browse 394,279 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55960 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub... |
| CVE-2026-55958 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding th... |
| CVE-2026-46602 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image cont... |
| CVE-2026-46601 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. |
| CVE-2026-37454 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit... |
| CVE-2026-37453 | HIGH | 7.5 | 0.4% | Jun 25, 2026 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit... |
| CVE-2026-37149 | HIGH | 7.7 | 0.2% | Jun 25, 2026 | GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil... |
| CVE-2026-2299 | MEDIUM | 4.3 | 0.1% | Jun 25, 2026 | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoi... |
| CVE-2026-12340 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 si... |
| CVE-2026-11310 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects on... |
| CVE-2026-10592 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca... |
| CVE-2026-10512 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so... |
| CVE-2026-10097 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during t... |
| CVE-2025-60465 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02... |
| CVE-2025-60464 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.... |
| CVE-2026-57700 | CRITICAL | 10 | 0.4% | Jun 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This i... |
| CVE-2026-56790 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() funct... |
| CVE-2026-56789 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allow... |
| CVE-2026-56788 | HIGH | 7.1 | 0.1% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RI... |
| CVE-2026-56787 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:... |
| CVE-2026-56786 | CRITICAL | 9.8 | 0.4% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp lengt... |
| CVE-2026-56779 | MEDIUM | 6.4 | 0.2% | Jun 25, 2026 | MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allo... |
| CVE-2026-56774 | MEDIUM | 5.4 | 0.3% | Jun 25, 2026 | Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id par... |
| CVE-2026-56772 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private no... |
| CVE-2026-56771 | HIGH | 8.5 | 0.2% | Jun 25, 2026 | NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows ... |
