CVE Vulnerability Database
Search and browse 394,408 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12846 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-12488 | MEDIUM | 6.2 | 0.2% | Jun 24, 2026 | A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially cr... |
| CVE-2026-12486 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12485 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-3652 | HIGH | 7.2 | 0.2% | Jun 24, 2026 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save... |
| CVE-2026-11614 | MEDIUM | 6.4 | 0.3% | Jun 24, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '... |
| CVE-2026-12681 | HIGH | 8.9 | 0.2% | Jun 24, 2026 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig... |
| CVE-2026-54639 | HIGH | 8.8 | 0.1% | Jun 24, 2026 | Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in... |
| CVE-2026-7574 | HIGH | 8.7 | 0.1% | Jun 24, 2026 | Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1... |
| CVE-2026-6458 | MEDIUM | 5.1 | 0.1% | Jun 24, 2026 | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authenticat... |
| CVE-2026-5818 | HIGH | 7.2 | 0.2% | Jun 24, 2026 | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) al... |
| CVE-2026-56785 | HIGH | 8.4 | 0.2% | Jun 23, 2026 | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email f... |
| CVE-2026-54588 | CRITICAL | 9.6 | 0.3% | Jun 23, 2026 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacke... |
| CVE-2026-48493 | MEDIUM | 5.5 | 0.2% | Jun 23, 2026 | Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PA... |
| CVE-2026-47693 | MEDIUM | 6.9 | 0.2% | Jun 23, 2026 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable ... |
| CVE-2026-12164 | MEDIUM | 4.4 | 0.1% | Jun 23, 2026 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or el... |
| CVE-2026-12163 | MEDIUM | 4.8 | 0.2% | Jun 23, 2026 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-s... |
| CVE-2026-11972 | HIGH | 8.2 | 0.4% | Jun 23, 2026 | When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h... |
| CVE-2026-54518 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-9073 | MEDIUM | 6.2 | 0.2% | Jun 23, 2026 | A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitiv... |
| CVE-2026-56120 | — | — | — | Jun 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-20... |
| CVE-2026-54517 | MEDIUM | 5.3 | 0.2% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-54516 | MEDIUM | 5.3 | 0.3% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-54515 | MEDIUM | 5.3 | 0.4% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-54514 | MEDIUM | 5.3 | 0.2% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
