CVE Vulnerability Database
Search and browse 394,759 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48779 | HIGH | 7.5 | 0.8% | Jun 17, 2026 | ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f... |
| CVE-2026-48745 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca... |
| CVE-2026-48616 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L... |
| CVE-2026-48055 | CRITICAL | 10 | 0.6% | Jun 17, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,... |
| CVE-2026-47340 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ... |
| CVE-2026-47277 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro... |
| CVE-2026-45436 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions. |
| CVE-2026-44587 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ... |
| CVE-2026-42629 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. |
| CVE-2026-42385 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions. |
| CVE-2026-42380 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| CVE-2026-42357 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do... |
| CVE-2026-41557 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions. |
| CVE-2026-41280 | MEDIUM | 4.9 | 0.4% | Jun 17, 2026 | Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthoriz... |
| CVE-2026-40783 | CRITICAL | 9.9 | 0.5% | Jun 17, 2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. |
| CVE-2026-40768 | HIGH | 7.3 | 0.3% | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. |
| CVE-2026-40765 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions. |
| CVE-2026-40761 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. |
| CVE-2026-40760 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Behold <= 1.5 versions. |
| CVE-2026-40759 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Esmée <= 1.4 versions. |
| CVE-2026-40758 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions. |
| CVE-2026-40755 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in TechLink <= 1.3 versions. |
| CVE-2026-40754 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Roisin <= 1.4 versions. |
| CVE-2026-40753 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions. |
| CVE-2026-40751 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions. |
