CVE Vulnerability Database
Search and browse 395,159 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42890 | MEDIUM | 4.8 | 0.1% | Jun 12, 2026 | Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron ... |
| CVE-2026-42851 | HIGH | 7.8 | 0.2% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term... |
| CVE-2026-42850 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the ... |
| CVE-2026-42604 | MEDIUM | 6.9 | 0.4% | Jun 12, 2026 | Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server version... |
| CVE-2026-53726 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-53725 | MEDIUM | 5.9 | 0.3% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8... |
| CVE-2026-53724 | LOW | 2.1 | 0.3% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-53408 | HIGH | 8.1 | 0.2% | Jun 12, 2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.... |
| CVE-2026-53407 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.... |
| CVE-2026-50244 | MEDIUM | 6.9 | 0.2% | Jun 12, 2026 | The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbit... |
| CVE-2026-50108 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifyin... |
| CVE-2026-50101 | CRITICAL | 9.2 | 0.3% | Jun 12, 2026 | Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each... |
| CVE-2026-50099 | MEDIUM | 5.1 | 0.2% | Jun 12, 2026 | During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in clearte... |
| CVE-2026-50008 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8... |
| CVE-2026-47248 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-47236 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view a... |
| CVE-2026-47138 | HIGH | 8.7 | 0.6% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-42947 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently... |
| CVE-2026-42932 | MEDIUM | 6.9 | 0.2% | Jun 12, 2026 | Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predict... |
| CVE-2026-42306 | HIGH | 7.2 | 0.1% | Jun 12, 2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ... |
| CVE-2026-41568 | MEDIUM | 6.1 | 0.1% | Jun 12, 2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ... |
| CVE-2026-28742 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmwar... |
| CVE-2026-12143 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argumen... |
| CVE-2026-12043 | HIGH | 8.8 | 0.4% | Jun 12, 2026 | Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote ... |
| CVE-2026-10715 | MEDIUM | 5.1 | 0.2% | Jun 12, 2026 | Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-... |
