CVE Vulnerability Database
Search and browse 395,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11967 | HIGH | 8.5 | 0.1% | Jun 12, 2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma... |
| CVE-2026-11879 | HIGH | 8.5 | 0.1% | Jun 12, 2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali... |
| CVE-2017-20240 | MEDIUM | 5.9 | 0.3% | Jun 12, 2026 | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq... |
| CVE-2026-49347 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly ... |
| CVE-2026-48485 | LOW | 2.1 | 0.3% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un... |
| CVE-2026-47197 | HIGH | 7.2 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can... |
| CVE-2026-47196 | HIGH | 8.4 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re... |
| CVE-2026-47195 | HIGH | 7.1 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p... |
| CVE-2026-9266 | HIGH | 7 | 0.1% | Jun 12, 2026 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial... |
| CVE-2026-11849 | CRITICAL | 9.8 | 0.4% | Jun 12, 2026 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing una... |
| CVE-2026-11848 | HIGH | 7.9 | 0.3% | Jun 12, 2026 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una... |
| CVE-2026-50645 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache... |
| CVE-2026-50634 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was... |
| CVE-2026-50633 | HIGH | 8.1 | 0.9% | Jun 12, 2026 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec... |
| CVE-2026-50632 | HIGH | 8.1 | 0.6% | Jun 12, 2026 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache... |
| CVE-2026-50631 | HIGH | 7.4 | 0.3% | Jun 12, 2026 | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u... |
| CVE-2026-50630 | MEDIUM | 6.5 | 0.4% | Jun 12, 2026 | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate res... |
| CVE-2026-50629 | MEDIUM | 5.3 | 0.5% | Jun 12, 2026 | The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi... |
| CVE-2026-50628 | CRITICAL | 9.8 | 0.7% | Jun 12, 2026 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all... |
| CVE-2026-50627 | CRITICAL | 9.1 | 0.4% | Jun 12, 2026 | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok... |
| CVE-2026-50623 | MEDIUM | 4.8 | 0.4% | Jun 12, 2026 | An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 't... |
| CVE-2026-49875 | CRITICAL | 9.8 | 0.5% | Jun 12, 2026 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary... |
| CVE-2026-48914 | MEDIUM | 6.7 | 0.2% | Jun 12, 2026 | A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of... |
| CVE-2026-11847 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowi... |
| CVE-2026-11846 | HIGH | 8.1 | 0.4% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit... |
