CVE Vulnerability Database
Search and browse 394,993 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54411 | MEDIUM | 6.9 | 0.3% | Jun 14, 2026 | Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-passwor... |
| CVE-2026-54410 | HIGH | 8.6 | 0.5% | Jun 14, 2026 | nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP serv... |
| CVE-2026-11527 | HIGH | 8.6 | 0.6% | Jun 14, 2026 | Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of t... |
| CVE-2026-11526 | CRITICAL | 9.8 | 1.4% | Jun 14, 2026 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments ... |
| CVE-2025-15546 | MEDIUM | 5.4 | 0.2% | Jun 14, 2026 | The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy s... |
| CVE-2026-54421 | MEDIUM | 6.8 | 0.3% | Jun 14, 2026 | In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized fo... |
| CVE-2026-54420 | HIGH | 8.5 | 1.3% | Jun 14, 2026 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide... |
| CVE-2026-12176 | MEDIUM | 4.3 | 0.3% | Jun 14, 2026 | A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impa... |
| CVE-2026-12175 | MEDIUM | 4.7 | 0.2% | Jun 13, 2026 | A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of t... |
| CVE-2026-12174 | HIGH | 8.8 | 0.6% | Jun 13, 2026 | A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the f... |
| CVE-2026-12183 | CRITICAL | 9.8 | 0.5% | Jun 13, 2026 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentic... |
| CVE-2026-6428 | HIGH | 7.6 | 0.2% | Jun 13, 2026 | SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x b... |
| CVE-2026-5513 | HIGH | 7.2 | 0.3% | Jun 13, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-1291 | MEDIUM | 4.3 | 0.2% | Jun 13, 2026 | The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2026-11624 | CRITICAL | 9.4 | 0.2% | Jun 13, 2026 | The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne... |
| CVE-2026-9629 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up ... |
| CVE-2026-3297 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2026-2470 | MEDIUM | 4.3 | 0.2% | Jun 13, 2026 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio... |
| CVE-2026-9134 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod... |
| CVE-2026-9109 | HIGH | 7.2 | 0.3% | Jun 13, 2026 | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vu... |
| CVE-2026-9062 | LOW | 3.4 | 0.2% | Jun 13, 2026 | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h... |
| CVE-2026-9061 | LOW | 3.5 | 0.1% | Jun 13, 2026 | The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o... |
| CVE-2026-11769 | HIGH | 8.8 | 0.4% | Jun 13, 2026 | We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t... |
| CVE-2026-9848 | HIGH | 7.5 | 0.5% | Jun 13, 2026 | The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers... |
| CVE-2026-54231 | MEDIUM | 5.5 | 0.2% | Jun 13, 2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script... |
