CVE Vulnerability Database
Search and browse 394,301 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9651 | MEDIUM | 4.4 | 0.1% | Jun 25, 2026 | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of ... |
| CVE-2026-9650 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitiv... |
| CVE-2026-57456 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho... |
| CVE-2026-57455 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in ... |
| CVE-2026-57454 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a v... |
| CVE-2026-57453 | HIGH | 7.3 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.... |
| CVE-2026-57452 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04... |
| CVE-2026-57451 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 pr... |
| CVE-2026-57438 | MEDIUM | 6.6 | 0.1% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio... |
| CVE-2026-55895 | HIGH | 7.8 | 0.2% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s... |
| CVE-2026-55892 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a ... |
| CVE-2026-55693 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c f... |
| CVE-2026-55477 | HIGH | 7.2 | 0.3% | Jun 25, 2026 | 3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse th... |
| CVE-2026-54036 | HIGH | 8.1 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/en... |
| CVE-2026-4522 | MEDIUM | 6.7 | 0.1% | Jun 25, 2026 | Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti... |
| CVE-2026-48946 | MEDIUM | 6.3 | 0.2% | Jun 25, 2026 | The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php ma... |
| CVE-2026-48945 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only re... |
| CVE-2026-48944 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SI... |
| CVE-2026-48943 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by inc... |
| CVE-2026-48942 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both... |
| CVE-2026-48941 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad... |
| CVE-2026-48940 | LOW | 3.4 | 0.2% | Jun 25, 2026 | A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field ... |
| CVE-2026-12844 | HIGH | 7.5 | 0.4% | Jun 25, 2026 | List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() coll... |
| CVE-2026-6432 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage. |
| CVE-2026-57588 | LOW | 3.3 | 0.2% | Jun 25, 2026 | A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by ... |
