CVE Vulnerability Database
Search and browse 394,518 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4610 | MEDIUM | 6.4 | 0.2% | Jun 23, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2026-44089 | CRITICAL | 9.4 | 0.2% | Jun 23, 2026 | Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. Thi... |
| CVE-2026-10857 | MEDIUM | 6.1 | 0.1% | Jun 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Comp... |
| CVE-2026-10711 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Lt... |
| CVE-2025-71376 | HIGH | 8.1 | 0.3% | Jun 23, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completion... |
| CVE-2025-71370 | HIGH | 8.1 | 0.4% | Jun 23, 2026 | picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded ... |
| CVE-2025-71365 | HIGH | 8.1 | 0.3% | Jun 23, 2026 | picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function thro... |
| CVE-2025-71341 | HIGH | 8.1 | 0.5% | Jun 23, 2026 | picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attac... |
| CVE-2025-71337 | HIGH | 8.7 | 0.3% | Jun 23, 2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authen... |
| CVE-2023-54365 | HIGH | 8.7 | 0.6% | Jun 23, 2026 | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri... |
| CVE-2026-4983 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content... |
| CVE-2026-11374 | CRITICAL | 9 | 1.2% | Jun 23, 2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated... |
| CVE-2026-9733 | CRITICAL | 9.1 | 0.3% | Jun 23, 2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no... |
| CVE-2026-10521 | HIGH | 8.6 | 0.3% | Jun 23, 2026 | An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, ... |
| CVE-2026-8379 | HIGH | 7.5 | 0.2% | Jun 23, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file dow... |
| CVE-2026-8378 | MEDIUM | 5.4 | 0.1% | Jun 23, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the ... |
| CVE-2026-8172 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it... |
| CVE-2026-8163 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using t... |
| CVE-2026-7842 | MEDIUM | 6.8 | 0.2% | Jun 23, 2026 | The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde... |
| CVE-2026-12866 | CRITICAL | 9.8 | 0.5% | Jun 23, 2026 | All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu... |
| CVE-2026-55655 | MEDIUM | 6.1 | 0.1% | Jun 23, 2026 | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding ... |
| CVE-2026-55654 | LOW | 3.7 | 0.4% | Jun 23, 2026 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic... |
| CVE-2026-55653 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group ... |
| CVE-2026-11833 | HIGH | 8.2 | 0.2% | Jun 23, 2026 | Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t... |
| CVE-2026-10658 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the... |
