CVE Vulnerability Database
Search and browse 397,817 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41577 | HIGH | 7.5 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces... |
| CVE-2026-40181 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to th... |
| CVE-2026-38967 | CRITICAL | 9.8 | 0.3% | Jun 2, 2026 | CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. |
| CVE-2026-35202 | LOW | 2.3 | 0.2% | Jun 2, 2026 | Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has... |
| CVE-2026-35049 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted m... |
| CVE-2026-34993 | HIGH | 7.3 | 0.2% | Jun 2, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ... |
| CVE-2026-34077 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co... |
| CVE-2026-33553 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS. |
| CVE-2026-33245 | MEDIUM | 4.7 | 0.2% | Jun 2, 2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co... |
| CVE-2026-30586 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information v... |
| CVE-2026-28299 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause... |
| CVE-2026-1829 | HIGH | 8.8 | 0.7% | Jun 2, 2026 | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t... |
| CVE-2026-10702 | MEDIUM | 4.3 | 0.6% | Jun 2, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. |
| CVE-2026-10701 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3. |
| CVE-2026-10617 | HIGH | 7.3 | 0.4% | Jun 2, 2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAut... |
| CVE-2026-10616 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTo... |
| CVE-2026-10608 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyactio... |
| CVE-2026-10607 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file... |
| CVE-2026-10584 | HIGH | 8.2 | 0.1% | Jun 2, 2026 | Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow rem... |
| CVE-2025-64390 | HIGH | 7.4 | 0.1% | Jun 2, 2026 | A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di... |
| CVE-2021-4479 | MEDIUM | 6.3 | 0.2% | Jun 2, 2026 | Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnerability that allows a... |
| CVE-2021-4478 | HIGH | 8.3 | 0.1% | Jun 2, 2026 | Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerabili... |
| CVE-2019-25724 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of ser... |
| CVE-2019-25723 | MEDIUM | 6.3 | 0.2% | Jun 2, 2026 | Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows ex... |
| CVE-2019-25722 | HIGH | 7.6 | 0.2% | Jun 2, 2026 | Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentia... |
