CVE Vulnerability Database
Search and browse 397,790 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10873 | HIGH | 7.3 | 2.7% | Jun 4, 2026 | A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats ... |
| CVE-2026-10872 | HIGH | 7.3 | 2.6% | Jun 4, 2026 | A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/... |
| CVE-2025-8873 | HIGH | 8.7 | 0.4% | Jun 4, 2026 | On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to st... |
| CVE-2024-27892 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2024-27891 | MEDIUM | 6.9 | 0.3% | Jun 4, 2026 | On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies... |
| CVE-2024-27890 | CRITICAL | 9.6 | 4.4% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2023-5502 | HIGH | 8.2 | 0.3% | Jun 4, 2026 | On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing en... |
| CVE-2026-42547 | MEDIUM | 5.4 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In ve... |
| CVE-2026-42543 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-42540 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-42539 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-11322 | HIGH | 7.1 | 0.3% | Jun 4, 2026 | Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace bo... |
| CVE-2026-10871 | HIGH | 7.3 | 2.2% | Jun 4, 2026 | A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of t... |
| CVE-2024-6858 | MEDIUM | 6.5 | 0.1% | Jun 4, 2026 | In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there ... |
| CVE-2026-5066 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/... |
| CVE-2026-42538 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-42329 | MEDIUM | 4.7 | 0.2% | Jun 4, 2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-10870 | HIGH | 7.3 | 2.2% | Jun 4, 2026 | A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the comp... |
| CVE-2026-5589 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati... |
| CVE-2026-41522 | HIGH | 7.1 | 0.2% | Jun 4, 2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior... |
| CVE-2026-41518 | HIGH | 7.6 | 0.2% | Jun 4, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-41249 | HIGH | 8.2 | 0.4% | Jun 4, 2026 | CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow ... |
| CVE-2026-21404 | MEDIUM | 6.3 | 0.1% | Jun 4, 2026 | NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOA... |
| CVE-2026-48480 | MEDIUM | 6.6 | 0.2% | Jun 4, 2026 | The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp im... |
| CVE-2026-41237 | HIGH | 8.6 | 0.3% | Jun 4, 2026 | Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` whi... |
