CVE Vulnerability Database
Search and browse 395,582 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44705 | HIGH | 8.2 | 0.4% | Jun 11, 2026 | tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal... |
| CVE-2026-44496 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor... |
| CVE-2026-44495 | HIGH | 7.7 | 0.8% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain... |
| CVE-2026-44494 | HIGH | 8.7 | 1.0% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln... |
| CVE-2026-44492 | HIGH | 8.6 | 0.9% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I... |
| CVE-2026-44490 | HIGH | 8.2 | 0.3% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-sid... |
| CVE-2026-44489 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b... |
| CVE-2026-44488 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co... |
| CVE-2026-44487 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt... |
| CVE-2026-44486 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte... |
| CVE-2026-11945 | HIGH | 7.5 | 0.2% | Jun 11, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON docume... |
| CVE-2026-9648 | CRITICAL | 9.1 | 0.2% | Jun 11, 2026 | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certi... |
| CVE-2026-7870 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici... |
| CVE-2026-7787 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass... |
| CVE-2026-53777 | HIGH | 8.6 | 0.4% | Jun 11, 2026 | Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co... |
| CVE-2026-4096 | MEDIUM | 6.1 | 0.1% | Jun 11, 2026 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th... |
| CVE-2026-3341 | MEDIUM | 5.4 | 0.1% | Jun 11, 2026 | IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo... |
| CVE-2026-11839 | CRITICAL | 9.9 | 0.3% | Jun 11, 2026 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows ... |
| CVE-2024-45636 | MEDIUM | 4.4 | 0.1% | Jun 11, 2026 | IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg... |
| CVE-2026-8406 | HIGH | 7.1 | 0.2% | Jun 11, 2026 | openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticate... |
| CVE-2026-6338 | MEDIUM | 4.9 | 0.3% | Jun 11, 2026 | A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13... |
| CVE-2026-53723 | MEDIUM | 5.8 | 0.2% | Jun 11, 2026 | Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri... |
| CVE-2026-53661 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden... |
| CVE-2026-38581 | CRITICAL | 9.8 | 0.3% | Jun 11, 2026 | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitra... |
| CVE-2026-11816 | HIGH | 8.1 | 0.5% | Jun 11, 2026 | Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `... |
