CVE Vulnerability Database
Search and browse 394,518 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44957 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earl... |
| CVE-2026-44956 | NONE | 0 | 0.3% | Jun 23, 2026 | Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑gener... |
| CVE-2026-44792 | CRITICAL | 9 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access... |
| CVE-2026-44791 | CRITICAL | 9.9 | 0.6% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe... |
| CVE-2026-44790 | HIGH | 8.8 | 0.6% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe... |
| CVE-2026-44789 | CRITICAL | 9.9 | 0.6% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe... |
| CVE-2026-42867 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to... |
| CVE-2026-34917 | MEDIUM | 4.3 | 0.3% | Jun 23, 2026 | Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication ... |
| CVE-2026-34916 | HIGH | 8.8 | 0.4% | Jun 23, 2026 | A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a l... |
| CVE-2026-34915 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a l... |
| CVE-2026-34914 | HIGH | 8.3 | 0.3% | Jun 23, 2026 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileg... |
| CVE-2026-34913 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ads... |
| CVE-2026-34912 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive... |
| CVE-2026-33760 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monito... |
| CVE-2026-13007 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati... |
| CVE-2026-12958 | HIGH | 8.5 | 0.1% | Jun 23, 2026 | Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust ... |
| CVE-2026-12957 | HIGH | 8.5 | 0.1% | Jun 23, 2026 | Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may all... |
| CVE-2026-11940 | HIGH | 7.8 | 0.8% | Jun 23, 2026 | tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference... |
| CVE-2025-61028 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser... |
| CVE-2025-61027 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61025 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser... |
| CVE-2025-61023 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61022 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o... |
| CVE-2025-61021 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den... |
| CVE-2025-61020 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ... |
