CVE Vulnerability Database
Search and browse 397,817 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10629 | HIGH | 7.4 | 0.2% | Jun 2, 2026 | SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (mi... |
| CVE-2026-10591 | HIGH | 8.8 | 0.4% | Jun 2, 2026 | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remot... |
| CVE-2026-10047 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler... |
| CVE-2026-10046 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memor... |
| CVE-2026-9844 | HIGH | 8.8 | 0.2% | Jun 2, 2026 | Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface mo... |
| CVE-2026-7313 | MEDIUM | 4.9 | 0.3% | Jun 2, 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 ... |
| CVE-2026-7312 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152... |
| CVE-2026-7201 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441... |
| CVE-2026-7198 | CRITICAL | 9.8 | 0.4% | Jun 2, 2026 | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unaut... |
| CVE-2026-7195 | HIGH | 8.1 | 0.5% | Jun 2, 2026 | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152,... |
| CVE-2026-49782 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-43965 | MEDIUM | 5.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa... |
| CVE-2026-42795 | MEDIUM | 5.1 | 0.1% | Jun 2, 2026 | Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th... |
| CVE-2026-41918 | MEDIUM | 5.9 | 0.2% | Jun 2, 2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio... |
| CVE-2026-39555 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askk... |
| CVE-2026-39553 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39552 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-35717 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth... |
| CVE-2026-32685 | MEDIUM | 4.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write... |
| CVE-2026-32250 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere... |
| CVE-2026-28116 | MEDIUM | 5.9 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr... |
| CVE-2026-27351 | MEDIUM | 5.4 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-10622 | HIGH | 8.2 | 0.4% | Jun 2, 2026 | Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged fun... |
| CVE-2026-10621 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archi... |
| CVE-2026-10611 | CRITICAL | 10 | 0.4% | Jun 2, 2026 | An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In... |
