CVE Vulnerability Database
Search and browse 394,603 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10561 | CRITICAL | 10 | 0.5% | Jun 22, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with... |
| CVE-2025-66389 | HIGH | 7.5 | 0.4% | Jun 22, 2026 | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler... |
| CVE-2025-33128 | MEDIUM | 5.4 | 0.1% | Jun 22, 2026 | IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerab... |
| CVE-2025-2669 | MEDIUM | 6.5 | 0.2% | Jun 22, 2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri... |
| CVE-2024-54178 | MEDIUM | 6.5 | 0.2% | Jun 22, 2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen... |
| CVE-2026-56422 | CRITICAL | 9.4 | 0.4% | Jun 22, 2026 | Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (i... |
| CVE-2026-11373 | CRITICAL | 9.1 | 0.4% | Jun 22, 2026 | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for th... |
| CVE-2026-12863 | MEDIUM | 5.1 | 0.2% | Jun 22, 2026 | An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using... |
| CVE-2026-12862 | MEDIUM | 5.1 | 0.2% | Jun 22, 2026 | Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be... |
| CVE-2026-12581 | HIGH | 7.7 | 0.3% | Jun 22, 2026 | EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s... |
| CVE-2026-12580 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attack... |
| CVE-2025-4994 | HIGH | 8.7 | 0.2% | Jun 22, 2026 | The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authenticatio... |
| CVE-2023-45796 | HIGH | 8.1 | 0.3% | Jun 22, 2026 | A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to an... |
| CVE-2023-45795 | HIGH | 7.8 | 0.1% | Jun 22, 2026 | A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticat... |
| CVE-2026-54665 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an... |
| CVE-2026-44914 | HIGH | 7.2 | 0.4% | Jun 22, 2026 | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension componen... |
| CVE-2026-44913 | HIGH | 7.2 | 0.4% | Jun 22, 2026 | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.... |
| CVE-2026-44911 | MEDIUM | 6.3 | 0.3% | Jun 22, 2026 | Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clie... |
| CVE-2025-66336 | HIGH | 8.1 | 0.3% | Jun 22, 2026 | Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name... |
| CVE-2025-62198 | MEDIUM | 5.4 | 0.3% | Jun 22, 2026 | An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommend... |
| CVE-2026-8157 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new u... |
| CVE-2026-7859 | MEDIUM | 5.3 | 0.1% | Jun 22, 2026 | The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action... |
| CVE-2026-6858 | HIGH | 7.1 | 0.2% | Jun 22, 2026 | The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthen... |
| CVE-2026-4259 | HIGH | 7.1 | 0.1% | Jun 22, 2026 | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp... |
| CVE-2026-4110 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp... |
