CVE Vulnerability Database
Search and browse 397,817 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49144 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js ... |
| CVE-2026-49143 | HIGH | 8.8 | 0.4% | Jun 2, 2026 | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows u... |
| CVE-2026-47201 | HIGH | 8.5 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou... |
| CVE-2026-45289 | MEDIUM | 5.3 | 0.1% | Jun 2, 2026 | CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526... |
| CVE-2026-42849 | CRITICAL | 9.3 | 0.4% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of st... |
| CVE-2026-41569 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-... |
| CVE-2026-10624 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unk... |
| CVE-2026-10620 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.... |
| CVE-2026-10619 | HIGH | 7.3 | 0.5% | Jun 2, 2026 | A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This ... |
| CVE-2026-8036 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially ... |
| CVE-2026-8035 | MEDIUM | 5.5 | 0.1% | Jun 2, 2026 | Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service ... |
| CVE-2026-5385 | HIGH | 8.4 | 0.4% | Jun 2, 2026 | An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. Thi... |
| CVE-2026-5076 | CRITICAL | 9.8 | 0.4% | Jun 2, 2026 | The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a... |
| CVE-2026-5074 | MEDIUM | 6.5 | 0.3% | Jun 2, 2026 | The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_priv... |
| CVE-2026-5073 | HIGH | 7.5 | 1.4% | Jun 2, 2026 | The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory... |
| CVE-2026-49120 | HIGH | 8.5 | 0.2% | Jun 2, 2026 | Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen... |
| CVE-2026-48682 | MEDIUM | 5.9 | 0.3% | Jun 2, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packe... |
| CVE-2026-48598 | LOW | 3.7 | 0.3% | Jun 2, 2026 | Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via u... |
| CVE-2026-48597 | MEDIUM | 5.9 | 0.6% | Jun 2, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via at... |
| CVE-2026-48596 | LOW | 3.7 | 0.3% | Jun 2, 2026 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-te... |
| CVE-2026-48595 | MEDIUM | 5.9 | 0.7% | Jun 2, 2026 | Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party ori... |
| CVE-2026-48594 | HIGH | 7.5 | 0.7% | Jun 2, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of ... |
| CVE-2026-47265 | HIGH | 7.5 | 0.1% | Jun 2, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set wit... |
| CVE-2026-42342 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 ... |
| CVE-2026-42211 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps ... |
