CVE Vulnerability Database
Search and browse 395,718 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53693 | MEDIUM | 6.9 | 0.3% | Jun 10, 2026 | A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa... |
| CVE-2026-49760 | MEDIUM | 5.5 | 0.1% | Jun 10, 2026 | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulner... |
| CVE-2026-49759 | HIGH | 8.2 | 0.5% | Jun 10, 2026 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to cra... |
| CVE-2026-48860 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated ... |
| CVE-2026-48859 | MEDIUM | 5.3 | 0.4% | Jun 10, 2026 | Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated rem... |
| CVE-2026-48858 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and S... |
| CVE-2026-48856 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Dat... |
| CVE-2026-48855 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows Fil... |
| CVE-2026-48096 | MEDIUM | 5.3 | 0.1% | Jun 10, 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is en... |
| CVE-2026-46558 | HIGH | 8.3 | 0.3% | Jun 10, 2026 | Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization ... |
| CVE-2026-46497 | LOW | 2.3 | 0.3% | Jun 10, 2026 | Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnera... |
| CVE-2026-45569 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, om... |
| CVE-2026-45567 | HIGH | 8.3 | 0.2% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th... |
| CVE-2026-45566 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th... |
| CVE-2026-45565 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, Es... |
| CVE-2026-25700 | HIGH | 7.2 | 0.4% | Jun 10, 2026 | Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: thr... |
| CVE-2026-9045 | HIGH | 8.5 | 0.1% | Jun 10, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manag... |
| CVE-2026-8637 | HIGH | 8.5 | 0.1% | Jun 10, 2026 | A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could a... |
| CVE-2026-8335 | HIGH | 7.1 | 0.2% | Jun 10, 2026 | A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute a... |
| CVE-2026-7516 | MEDIUM | 5.1 | 0.2% | Jun 10, 2026 | A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese mark... |
| CVE-2026-6090 | HIGH | 7.3 | 0.1% | Jun 10, 2026 | A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticate... |
| CVE-2026-53689 | HIGH | 7.1 | 0.2% | Jun 10, 2026 | libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection ... |
| CVE-2026-53476 | CRITICAL | 9.6 | 0.3% | Jun 10, 2026 | A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN),... |
| CVE-2026-53475 | HIGH | 7.4 | 0.3% | Jun 10, 2026 | A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connecti... |
| CVE-2026-53474 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a s... |
