CVE Vulnerability Database
Search and browse 397,814 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60477 | MEDIUM | 5 | 0.1% | Jun 3, 2026 | A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Pr... |
| CVE-2024-47273 | MEDIUM | 4.3 | 0.3% | Jun 3, 2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functiona... |
| CVE-2024-47263 | MEDIUM | 4.1 | 0.3% | Jun 3, 2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web... |
| CVE-2023-52951 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows ... |
| CVE-2022-49042 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backu... |
| CVE-2022-49036 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Ba... |
| CVE-2026-35085 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces... |
| CVE-2026-35084 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access ... |
| CVE-2026-35083 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. |
| CVE-2026-35082 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient... |
| CVE-2026-35081 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien... |
| CVE-2026-35080 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic... |
| CVE-2026-35079 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient... |
| CVE-2026-35078 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien... |
| CVE-2026-35077 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi... |
| CVE-2026-35076 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici... |
| CVE-2026-35075 | CRITICAL | 9.8 | 0.5% | Jun 3, 2026 | An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full a... |
| CVE-2026-10722 | MEDIUM | 5.5 | 0.2% | Jun 3, 2026 | A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go... |
| CVE-2025-41259 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivilege... |
| CVE-2026-47065 | CRITICAL | 9.8 | 0.5% | Jun 3, 2026 | ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Ful... |
| CVE-2026-41032 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some... |
| CVE-2025-15656 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe... |
| CVE-2025-15655 | HIGH | 7.6 | 0.2% | Jun 3, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Ma... |
| CVE-2025-14774 | HIGH | 7.4 | 0.2% | Jun 3, 2026 | Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. |
| CVE-2025-14773 | MEDIUM | 5.4 | 0.2% | Jun 3, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. T... |
