CVE Vulnerability Database
Search and browse 394,518 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35018 | HIGH | 8.8 | 0.7% | Jun 23, 2026 | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerabilit... |
| CVE-2026-28496 | CRITICAL | 9.4 | 1.9% | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Temp... |
| CVE-2026-27604 | CRITICAL | 10 | 0.4% | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version ... |
| CVE-2026-12969 | MEDIUM | 5.3 | 0.4% | Jun 23, 2026 | An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section re... |
| CVE-2026-11772 | MEDIUM | 5.1 | 0.4% | Jun 23, 2026 | DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that... |
| CVE-2026-10609 | MEDIUM | 6.8 | 0.2% | Jun 23, 2026 | A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv... |
| CVE-2026-56784 | HIGH | 8.6 | 0.3% | Jun 23, 2026 | OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion en... |
| CVE-2026-56762 | MEDIUM | 6.9 | 0.2% | Jun 23, 2026 | Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigne... |
| CVE-2026-56701 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allo... |
| CVE-2026-56379 | CRITICAL | 9.2 | 0.9% | Jun 23, 2026 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows atta... |
| CVE-2026-56376 | LOW | 3.3 | 0.2% | Jun 23, 2026 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails... |
| CVE-2026-56371 | MEDIUM | 5.3 | 0.2% | Jun 23, 2026 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture ... |
| CVE-2026-56322 | HIGH | 8.7 | 0.3% | Jun 23, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that res... |
| CVE-2026-56315 | CRITICAL | 9.8 | 0.8% | Jun 23, 2026 | picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _ai... |
| CVE-2026-56301 | MEDIUM | 6.8 | 0.1% | Jun 23, 2026 | Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit... |
| CVE-2026-56275 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers... |
| CVE-2026-56274 | CRITICAL | 9.9 | 2.7% | Jun 23, 2026 | Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to inco... |
| CVE-2026-56263 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl U... |
| CVE-2026-56258 | CRITICAL | 9.2 | 0.7% | Jun 23, 2026 | Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows una... |
| CVE-2026-56248 | HIGH | 8.7 | 0.4% | Jun 23, 2026 | Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from t... |
| CVE-2026-56243 | HIGH | 8.6 | 0.3% | Jun 23, 2026 | Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext A... |
| CVE-2026-56234 | MEDIUM | 6.9 | 0.2% | Jun 23, 2026 | Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password... |
| CVE-2026-56225 | HIGH | 8.7 | 0.3% | Jun 23, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/... |
| CVE-2026-56222 | HIGH | 8.6 | 0.4% | Jun 23, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify... |
| CVE-2026-54892 | HIGH | 8.7 | 0.7% | Jun 23, 2026 | Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause... |
