CVE Vulnerability Database
Search and browse 396,745 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11793 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co... |
| CVE-2026-11792 | LOW | 3.3 | 0.3% | Jun 9, 2026 | A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st... |
| CVE-2026-11790 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t... |
| CVE-2026-11789 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp... |
| CVE-2026-11788 | HIGH | 7.5 | 0.6% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us... |
| CVE-2026-11787 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without ... |
| CVE-2026-11786 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute ... |
| CVE-2026-11785 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st... |
| CVE-2026-46324 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink ... |
| CVE-2026-46323 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive()... |
| CVE-2026-46322 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(... |
| CVE-2026-46321 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_... |
| CVE-2026-46320 | HIGH | 7.4 | 0.2% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()... |
| CVE-2026-46319 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after... |
| CVE-2026-46318 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_... |
| CVE-2026-46317 | HIGH | 8.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l... |
| CVE-2026-46316 | CRITICAL | 9.3 | 0.4% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re... |
| CVE-2026-2638 | HIGH | 7.3 | 0.1% | Jun 9, 2026 | A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a loc... |
| CVE-2026-11764 | LOW | 3.6 | 0.2% | Jun 9, 2026 | When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if ... |
| CVE-2017-20251 | CRITICAL | 9.8 | 0.6% | Jun 9, 2026 | WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated... |
| CVE-2017-20250 | HIGH | 8.7 | 0.6% | Jun 9, 2026 | Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrar... |
| CVE-2017-20249 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit... |
| CVE-2017-20248 | HIGH | 8.7 | 0.6% | Jun 9, 2026 | Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbi... |
| CVE-2017-20247 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to... |
| CVE-2017-20246 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to r... |
