CVE Vulnerability Database
Search and browse 397,801 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50224 | MEDIUM | 4.9 | 0.2% | Jun 4, 2026 | The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l... |
| CVE-2026-50214 | CRITICAL | 9.8 | 0.2% | Jun 4, 2026 | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary... |
| CVE-2026-4881 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being... |
| CVE-2026-49771 | HIGH | 7.6 | 0.2% | Jun 4, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Galler... |
| CVE-2026-49510 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects ... |
| CVE-2026-47320 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Mani... |
| CVE-2026-47319 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. T... |
| CVE-2026-47318 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rl... |
| CVE-2026-47306 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss... |
| CVE-2026-10800 | LOW | 3.6 | 0.1% | Jun 4, 2026 | A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_featu... |
| CVE-2026-10305 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: be... |
| CVE-2026-50213 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b... |
| CVE-2026-50212 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user... |
| CVE-2026-50211 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious... |
| CVE-2026-50210 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re... |
| CVE-2026-50209 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres... |
| CVE-2026-50208 | CRITICAL | 9.4 | 0.1% | Jun 4, 2026 | High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc... |
| CVE-2026-50207 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read base... |
| CVE-2026-3820 | HIGH | 7.2 | 0.4% | Jun 4, 2026 | There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain admini... |
| CVE-2026-50206 | MEDIUM | 6.8 | 0.7% | Jun 4, 2026 | Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou... |
| CVE-2026-50205 | HIGH | 8.2 | 0.2% | Jun 4, 2026 | System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identifi... |
| CVE-2026-49204 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. |
| CVE-2026-49203 | HIGH | 8.3 | 0.2% | Jun 4, 2026 | Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof... |
| CVE-2026-49202 | HIGH | 8.6 | 0.3% | Jun 4, 2026 | Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S... |
| CVE-2026-49194 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire... |
