CVE Vulnerability Database
Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5068 | HIGH | 8.8 | 0.5% | Jun 9, 2026 | A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD... |
| CVE-2026-44083 | CRITICAL | 9.8 | 0.5% | Jun 9, 2026 | An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attack... |
| CVE-2026-41986 | LOW | 2.4 | 0.1% | Jun 9, 2026 | Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi... |
| CVE-2026-41985 | MEDIUM | 5.1 | 0.1% | Jun 9, 2026 | UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser... |
| CVE-2026-41984 | MEDIUM | 5.2 | 0.1% | Jun 9, 2026 | UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser... |
| CVE-2026-41983 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2026-41982 | MEDIUM | 6.4 | 0.1% | Jun 9, 2026 | Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availab... |
| CVE-2026-41981 | MEDIUM | 5.3 | 0.1% | Jun 9, 2026 | Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect av... |
| CVE-2026-41977 | MEDIUM | 5 | 0.1% | Jun 9, 2026 | DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability. |
| CVE-2026-41976 | MEDIUM | 6.6 | 0.1% | Jun 9, 2026 | Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-41974 | LOW | 3.6 | 0.1% | Jun 9, 2026 | Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff... |
| CVE-2026-41973 | MEDIUM | 5.9 | 0.1% | Jun 9, 2026 | Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability... |
| CVE-2026-41972 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili... |
| CVE-2025-62858 | MEDIUM | 6.5 | 0.4% | Jun 9, 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker... |
| CVE-2026-8981 | LOW | 3.5 | 0.1% | Jun 9, 2026 | The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros... |
| CVE-2026-5067 | CRITICAL | 9.8 | 0.6% | Jun 9, 2026 | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi... |
| CVE-2026-4986 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before ... |
| CVE-2026-41539 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remot... |
| CVE-2026-11572 | HIGH | 8.8 | 1.1% | Jun 9, 2026 | Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to impro... |
| CVE-2026-9662 | HIGH | 8.1 | 0.6% | Jun 9, 2026 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and in... |
| CVE-2026-9185 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi... |
| CVE-2026-8977 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_ac... |
| CVE-2026-8940 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-8910 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-8909 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3.... |
