CVE Vulnerability Database
Search and browse 397,801 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49193 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the... |
| CVE-2026-49192 | MEDIUM | 5.4 | 0.1% | Jun 4, 2026 | The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri... |
| CVE-2026-49191 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose... |
| CVE-2026-49190 | HIGH | 8.8 | 0.4% | Jun 4, 2026 | The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau... |
| CVE-2026-50219 | MEDIUM | 5.9 | 0.2% | Jun 4, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars... |
| CVE-2026-49189 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke ... |
| CVE-2026-49188 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u... |
| CVE-2026-49187 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. |
| CVE-2026-10805 | MEDIUM | 6.7 | 0.2% | Jun 4, 2026 | A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba... |
| CVE-2026-49186 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin... |
| CVE-2026-49185 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction... |
| CVE-2026-48681 | HIGH | 8.1 | 0.6% | Jun 4, 2026 | OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS... |
| CVE-2026-44917 | MEDIUM | 4.9 | 0.3% | Jun 4, 2026 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron... |
| CVE-2026-41283 | CRITICAL | 9.9 | 0.7% | Jun 4, 2026 | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha... |
| CVE-2026-41010 | HIGH | 8.7 | 0.1% | Jun 4, 2026 | ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "... |
| CVE-2026-8829 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::E... |
| CVE-2026-41860 | HIGH | 8.8 | 0.1% | Jun 4, 2026 | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq... |
| CVE-2026-41859 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth heade... |
| CVE-2026-41858 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities... |
| CVE-2026-41011 | HIGH | 8.7 | 0.1% | Jun 4, 2026 | PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz")... |
| CVE-2026-10597 | MEDIUM | 6.9 | 0.2% | Jun 4, 2026 | OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote a... |
| CVE-2026-8653 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in ... |
| CVE-2026-7764 | MEDIUM | 6.8 | 0.1% | Jun 4, 2026 | An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versio... |
| CVE-2026-10737 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability ... |
| CVE-2026-8722 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked fo... |
