CVE Vulnerability Database
Search and browse 396,279 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40376 | HIGH | 8.1 | 0.7% | Jun 9, 2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-40371 | HIGH | 8.8 | 0.6% | Jun 9, 2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized... |
| CVE-2026-3088 | MEDIUM | 6.5 | 0.4% | Jun 9, 2026 | Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque... |
| CVE-2026-38615 | CRITICAL | 9.8 | 0.8% | Jun 9, 2026 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. |
| CVE-2026-35188 | MEDIUM | 5 | 0.2% | Jun 9, 2026 | Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ... |
| CVE-2026-34692 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting ... |
| CVE-2026-34335 | HIGH | 7 | 0.2% | Jun 9, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca... |
| CVE-2026-34183 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P... |
| CVE-2026-34182 | CRITICAL | 9.1 | 0.2% | Jun 9, 2026 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe... |
| CVE-2026-34181 | HIGH | 7.4 | 0.2% | Jun 9, 2026 | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base... |
| CVE-2026-34180 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes ... |
| CVE-2026-33828 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. |
| CVE-2026-33113 | MEDIUM | 6.1 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-32193 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all... |
| CVE-2026-28301 | MEDIUM | 4.8 | 0.2% | Jun 9, 2026 | A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit... |
| CVE-2026-26142 | CRITICAL | 9.8 | 1.9% | Jun 9, 2026 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. |
| CVE-2026-24181 | HIGH | 7.3 | 0.1% | Jun 9, 2026 | NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes... |
| CVE-2026-24180 | HIGH | 7.3 | 0.2% | Jun 9, 2026 | NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes... |
| CVE-2026-22926 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. |
| CVE-2026-0420 | MEDIUM | 5.9 | 0.1% | Jun 9, 2026 | An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co... |
| CVE-2026-0419 | HIGH | 8 | 0.3% | Jun 9, 2026 | Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u... |
| CVE-2026-0418 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n... |
| CVE-2026-0417 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected ... |
| CVE-2026-0416 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini... |
| CVE-2026-0415 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t... |
