CVE Vulnerability Database
Search and browse 394,378 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56231 | HIGH | 7.6 | 0.2% | Jun 24, 2026 | Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId ... |
| CVE-2026-56223 | HIGH | 8.7 | 0.4% | Jun 24, 2026 | Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that all... |
| CVE-2026-13163 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai... |
| CVE-2026-13140 | LOW | 1.1 | 0.2% | Jun 24, 2026 | Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exp... |
| CVE-2026-12242 | HIGH | 8.8 | 0.5% | Jun 24, 2026 | The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and includin... |
| CVE-2025-71361 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem... |
| CVE-2025-71354 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun... |
| CVE-2025-71332 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation ... |
| CVE-2026-13150 | MEDIUM | 6.9 | 0.3% | Jun 24, 2026 | Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) ... |
| CVE-2026-52944 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a perm... |
| CVE-2026-52943 | HIGH | 7.8 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb... |
| CVE-2026-11968 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit |
| CVE-2026-10745 | HIGH | 7.9 | 0.3% | Jun 24, 2026 | Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows... |
| CVE-2026-7761 | HIGH | 8.8 | 0.5% | Jun 24, 2026 | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver... |
| CVE-2026-56052 | HIGH | 7.6 | 0.2% | Jun 24, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B... |
| CVE-2026-52942 | HIGH | 7.1 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set befo... |
| CVE-2026-52941 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid NULL deref of conn->lnk in smc_msg_e... |
| CVE-2026-52940 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: zero the whole vnet header in tun_put_user() ... |
| CVE-2026-52939 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler(... |
| CVE-2026-52938 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereference in bpf_sk_storage... |
| CVE-2026-52937 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tap: fix stack info leak in tap_ioctl() SIOCGIFHWAD... |
| CVE-2026-52936 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock ... |
| CVE-2026-52935 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial... |
| CVE-2026-52934 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets ba... |
| CVE-2026-52933 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get... |
