CVE Vulnerability Database
Search and browse 394,365 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53949 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public ... |
| CVE-2026-53948 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied C... |
| CVE-2026-53947 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign... |
| CVE-2026-53946 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch mis... |
| CVE-2026-53945 | MEDIUM | 4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP reques... |
| CVE-2026-53944 | MEDIUM | 5.8 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible t... |
| CVE-2026-53943 | CRITICAL | 9.6 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that resul... |
| CVE-2026-49980 | CRITICAL | 9.8 | 0.8% | Jun 24, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.... |
| CVE-2026-49247 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint a... |
| CVE-2026-49246 | LOW | 1.7 | 0.3% | Jun 24, 2026 | Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forge... |
| CVE-2026-49220 | MEDIUM | 5.7 | 0.2% | Jun 24, 2026 | Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which c... |
| CVE-2026-48793 | HIGH | 8.8 | 0.4% | Jun 24, 2026 | Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerabil... |
| CVE-2026-13038 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbi... |
| CVE-2026-13037 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitr... |
| CVE-2026-13036 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-13035 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitra... |
| CVE-2026-13034 | MEDIUM | 4.7 | 0.1% | Jun 24, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had com... |
| CVE-2026-13033 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker ... |
| CVE-2026-13032 | CRITICAL | 9.6 | 0.2% | Jun 24, 2026 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per... |
| CVE-2026-13031 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-13030 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potenti... |
| CVE-2026-13029 | HIGH | 7.5 | 0.1% | Jun 24, 2026 | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user t... |
| CVE-2026-13028 | CRITICAL | 9.6 | 0.2% | Jun 24, 2026 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per... |
| CVE-2026-13027 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit h... |
| CVE-2026-13026 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to poten... |
