CVE Vulnerability Database
Search and browse 397,801 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25731 | MEDIUM | 6.1 | 0.2% | Jun 4, 2026 | Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject m... |
| CVE-2019-25730 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ... |
| CVE-2019-25729 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute ... |
| CVE-2019-25728 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL... |
| CVE-2019-25727 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated atta... |
| CVE-2019-25726 | HIGH | 8.8 | 0.3% | Jun 4, 2026 | All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute... |
| CVE-2026-4104 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and ... |
| CVE-2026-45432 | HIGH | 8.7 | 0.2% | Jun 4, 2026 | This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i... |
| CVE-2026-45431 | HIGH | 8.7 | 0.4% | Jun 4, 2026 | This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic ... |
| CVE-2026-10843 | HIGH | 7.2 | 0.3% | Jun 4, 2026 | A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro... |
| CVE-2026-10840 | HIGH | 7.1 | 0.2% | Jun 4, 2026 | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys... |
| CVE-2026-10804 | MEDIUM | 4.7 | 0.1% | Jun 4, 2026 | A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/r... |
| CVE-2026-10803 | LOW | 3.6 | 0.1% | Jun 4, 2026 | A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflo... |
| CVE-2026-10802 | MEDIUM | 4.3 | 0.3% | Jun 4, 2026 | A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the libra... |
| CVE-2025-52612 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script... |
| CVE-2025-52611 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ... |
| CVE-2025-52609 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by... |
| CVE-2025-52608 | MEDIUM | 4.3 | 0.1% | Jun 4, 2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s... |
| CVE-2025-52606 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar... |
| CVE-2025-12694 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t... |
| CVE-2026-49077 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMembe... |
| CVE-2026-10801 | LOW | 3.6 | 0.1% | Jun 4, 2026 | A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_... |
| CVE-2026-8916 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: b... |
| CVE-2026-50226 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrar... |
| CVE-2026-50225 | CRITICAL | 9.1 | 0.2% | Jun 4, 2026 | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t... |
