CVE Vulnerability Database
Search and browse 394,738 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9692 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id ... |
| CVE-2026-55392 | MEDIUM | 6.7 | 0.1% | Jun 18, 2026 | NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size ... |
| CVE-2026-48937 | HIGH | 7.5 | 0.5% | Jun 18, 2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v... |
| CVE-2026-47833 | MEDIUM | 6.9 | 0.1% | Jun 18, 2026 | setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A comp... |
| CVE-2026-12390 | HIGH | 7.8 | 0.1% | Jun 18, 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using spe... |
| CVE-2026-54390 | CRITICAL | 9.8 | 0.3% | Jun 18, 2026 | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticate... |
| CVE-2026-48986 | MEDIUM | 4.7 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_... |
| CVE-2026-48985 | MEDIUM | 5.5 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_... |
| CVE-2026-48984 | MEDIUM | 4.7 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre... |
| CVE-2026-12475 | — | — | — | Jun 18, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-56024 | MEDIUM | 6.5 | 0.1% | Jun 18, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue ... |
| CVE-2026-56022 | MEDIUM | 6.9 | 0.5% | Jun 18, 2026 | Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a... |
| CVE-2026-56021 | MEDIUM | 6.9 | 0.5% | Jun 18, 2026 | Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due ... |
| CVE-2026-56020 | CRITICAL | 9.2 | 0.5% | Jun 18, 2026 | The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL clie... |
| CVE-2026-55237 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-55205 | MEDIUM | 5.3 | 0.5% | Jun 18, 2026 | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oa... |
| CVE-2026-55204 | HIGH | 8.7 | 0.4% | Jun 18, 2026 | HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert()... |
| CVE-2026-55203 | CRITICAL | 9.1 | 0.3% | Jun 18, 2026 | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's ... |
| CVE-2026-54106 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-54105 | MEDIUM | 6.9 | 0.3% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-54104 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-54103 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-48617 | HIGH | 8.2 | 0.2% | Jun 18, 2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This... |
| CVE-2026-38718 | HIGH | 7.5 | 0.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a bu... |
| CVE-2026-38717 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
