CVE Vulnerability Database
Search and browse 394,742 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3490 | CRITICAL | 10 | 0.6% | Jun 17, 2026 | picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolv... |
| CVE-2026-36418 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressi... |
| CVE-2026-35069 | HIGH | 8 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a... |
| CVE-2026-35068 | MEDIUM | 5.7 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a... |
| CVE-2026-32652 | HIGH | 7.8 | 0.1% | Jun 17, 2026 | Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged att... |
| CVE-2026-20246 | MEDIUM | 6 | 0.1% | Jun 17, 2026 | A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to e... |
| CVE-2026-20220 | MEDIUM | 6.3 | 0.3% | Jun 17, 2026 | A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti... |
| CVE-2026-20190 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information o... |
| CVE-2026-20181 | CRITICAL | 9.1 | 0.7% | Jun 17, 2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on ... |
| CVE-2026-1288 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL... |
| CVE-2026-12515 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec... |
| CVE-2026-12151 | HIGH | 7.5 | 0.8% | Jun 17, 2026 | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but d... |
| CVE-2025-71325 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes... |
| CVE-2025-71323 | CRITICAL | 9.8 | 0.8% | Jun 17, 2026 | picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoki... |
| CVE-2025-71322 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypas... |
| CVE-2025-71321 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous ... |
| CVE-2025-71320 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller fun... |
| CVE-2025-32748 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticate... |
| CVE-2025-26240 | HIGH | 8.4 | 0.4% | Jun 17, 2026 | In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t... |
| CVE-2026-55748 | MEDIUM | 6 | 0.2% | Jun 17, 2026 | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ... |
| CVE-2026-55743 | CRITICAL | 9.6 | 0.7% | Jun 17, 2026 | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec... |
| CVE-2026-54812 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot... |
| CVE-2026-54810 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-54415 | HIGH | 8.6 | 0.3% | Jun 17, 2026 | Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all pla... |
| CVE-2026-49502 | HIGH | 8.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic... |
