CVE Vulnerability Database
Search and browse 394,846 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50869 | CRITICAL | 9.8 | 0.7% | Jun 15, 2026 | An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplyi... |
| CVE-2026-49954 | HIGH | 8.6 | 0.5% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated a... |
| CVE-2026-49953 | MEDIUM | 6.9 | 0.4% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo... |
| CVE-2026-49952 | CRITICAL | 9.3 | 0.5% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica... |
| CVE-2026-48114 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab... |
| CVE-2026-47835 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearc... |
| CVE-2026-45390 | CRITICAL | 9.1 | 0.4% | Jun 15, 2026 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire... |
| CVE-2026-45389 | HIGH | 7.4 | 0.2% | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client ... |
| CVE-2026-45388 | CRITICAL | 9.1 | 0.2% | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,... |
| CVE-2026-41708 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service ... |
| CVE-2026-39197 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-39196 | CRITICAL | 9.8 | 0.3% | Jun 15, 2026 | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in th... |
| CVE-2026-39118 | HIGH | 8.4 | 0.1% | Jun 15, 2026 | An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client valid... |
| CVE-2026-39007 | HIGH | 7.5 | 0.4% | Jun 15, 2026 | An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via th... |
| CVE-2026-39006 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component... |
| CVE-2026-38812 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generatio... |
| CVE-2026-38329 | CRITICAL | 9.8 | 0.6% | Jun 15, 2026 | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoi... |
| CVE-2026-38065 | CRITICAL | 9.8 | 1.3% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ... |
| CVE-2026-38064 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNu... |
| CVE-2026-38063 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via... |
| CVE-2026-38062 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the rat... |
| CVE-2026-38061 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volum... |
| CVE-2026-38060 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin p... |
| CVE-2026-37216 | MEDIUM | 6.1 | 0.2% | Jun 15, 2026 | Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add. |
| CVE-2026-36933 | MEDIUM | 6.8 | 0.2% | Jun 15, 2026 | An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi... |
