CVE Vulnerability Database
Search and browse 394,603 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33854 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a... |
| CVE-2026-9162 | MEDIUM | 4.3 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached ... |
| CVE-2026-9029 | MEDIUM | 5.4 | 0.3% | Jun 22, 2026 | A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer ... |
| CVE-2026-8074 | LOW | 3.8 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user act... |
| CVE-2026-7167 | MEDIUM | 6.9 | 0.4% | Jun 22, 2026 | The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,... |
| CVE-2026-7166 | CRITICAL | 9.2 | 0.4% | Jun 22, 2026 | Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p... |
| CVE-2026-7165 | CRITICAL | 9.4 | 0.3% | Jun 22, 2026 | The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a... |
| CVE-2026-6673 | MEDIUM | 6.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlas... |
| CVE-2026-6653 | CRITICAL | 9.8 | 0.3% | Jun 22, 2026 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker ... |
| CVE-2026-6062 | MEDIUM | 6.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel o... |
| CVE-2026-5139 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administra... |
| CVE-2026-56450 | MEDIUM | 5.1 | 0.3% | Jun 22, 2026 | AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac... |
| CVE-2026-56448 | HIGH | 8.3 | 0.3% | Jun 22, 2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e4... |
| CVE-2026-56447 | HIGH | 7.2 | 0.3% | Jun 22, 2026 | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path... |
| CVE-2026-56446 | HIGH | 7.2 | 0.4% | Jun 22, 2026 | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool... |
| CVE-2026-56425 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat... |
| CVE-2026-56424 | HIGH | 8.8 | 0.4% | Jun 22, 2026 | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent... |
| CVE-2026-56423 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af... |
| CVE-2026-54100 | HIGH | 8.3 | 0.3% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe... |
| CVE-2026-54099 | HIGH | 8.8 | 0.1% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au... |
| CVE-2026-42129 | HIGH | 7.7 | 0.4% | Jun 22, 2026 | A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp... |
| CVE-2026-28381 | HIGH | 8.1 | 0.2% | Jun 22, 2026 | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da... |
| CVE-2026-12888 | LOW | 2 | 0.3% | Jun 22, 2026 | An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canaryt... |
| CVE-2026-12602 | HIGH | 8.8 | 0.1% | Jun 22, 2026 | Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig... |
| CVE-2026-10601 | MEDIUM | 4.3 | 0.3% | Jun 22, 2026 | A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni... |
