CVE Vulnerability Database
Search and browse 395,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44976 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard... |
| CVE-2026-44975 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res... |
| CVE-2026-44967 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m... |
| CVE-2026-44208 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su... |
| CVE-2026-44207 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a... |
| CVE-2026-44206 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi... |
| CVE-2026-40677 | HIGH | 7.7 | 0.4% | Jun 12, 2026 | The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta... |
| CVE-2026-8694 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack... |
| CVE-2026-7368 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether ... |
| CVE-2026-6853 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry ... |
| CVE-2026-6211 | HIGH | 8.7 | 0.2% | Jun 12, 2026 | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access... |
| CVE-2026-54133 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON doc... |
| CVE-2026-53787 | CRITICAL | 9.8 | 3.7% | Jun 12, 2026 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerabili... |
| CVE-2026-53722 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not vali... |
| CVE-2026-53721 | HIGH | 8.2 | 0.3% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4... |
| CVE-2026-47739 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl... |
| CVE-2026-47244 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-47210 | CRITICAL | 9.8 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbi... |
| CVE-2026-47209 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)... |
| CVE-2026-47208 | CRITICAL | 10 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability... |
| CVE-2026-47141 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu... |
| CVE-2026-47140 | CRITICAL | 10 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins ... |
| CVE-2026-47139 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins... |
| CVE-2026-47137 | CRITICAL | 10 | 0.4% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) ... |
| CVE-2026-47135 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only inte... |
