CVE Vulnerability Database
Search and browse 394,330 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54823 | CRITICAL | 9.9 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. |
| CVE-2026-54822 | HIGH | 8.5 | 0.3% | Jun 25, 2026 | Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. |
| CVE-2026-54821 | HIGH | 7.4 | 0.3% | Jun 25, 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. |
| CVE-2026-52690 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D... |
| CVE-2026-4526 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logi... |
| CVE-2026-49506 | HIGH | 7.2 | 0.5% | Jun 25, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted ... |
| CVE-2026-47154 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating ... |
| CVE-2026-47153 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-ze... |
| CVE-2026-47152 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-ze... |
| CVE-2026-47151 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock... |
| CVE-2026-47150 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write a... |
| CVE-2026-47149 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table re... |
| CVE-2026-47148 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the me... |
| CVE-2026-47147 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limi... |
| CVE-2026-47146 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ... |
| CVE-2026-47145 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ... |
| CVE-2026-46734 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulner... |
| CVE-2026-46733 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerabil... |
| CVE-2026-46732 | HIGH | 7 | 0.1% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resou... |
| CVE-2026-42390 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured wit... |
| CVE-2026-42389 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative ... |
| CVE-2026-42388 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | Incomplete validation of the SOA record present in a catalog zone might lead to a crash. |
| CVE-2026-42387 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recur... |
| CVE-2026-41120 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust... |
| CVE-2026-40012 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have... |
