CVE Vulnerability Database
Search and browse 397,817 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69369 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68886 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58897 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58707 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2019-25719 | HIGH | 8.8 | 0.1% | Jun 2, 2026 | Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0... |
| CVE-2019-25717 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows ... |
| CVE-2026-8993 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Applicatio... |
| CVE-2026-42685 | HIGH | 7.1 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Porta... |
| CVE-2026-42684 | CRITICAL | 9.3 | 0.3% | Jun 2, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Porta... |
| CVE-2026-42670 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploitin... |
| CVE-2026-42669 | HIGH | 7.5 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Level... |
| CVE-2026-39551 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbe... |
| CVE-2026-39550 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects A... |
| CVE-2025-58705 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58024 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53440 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-5422 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check... |
| CVE-2026-5191 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da... |
| CVE-2026-46718 | MEDIUM | 6.5 | 0.4% | Jun 2, 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. Thi... |
| CVE-2026-41115 | MEDIUM | 4.3 | 0.3% | Jun 2, 2026 | An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_D... |
| CVE-2026-34907 | MEDIUM | 5.1 | 0.3% | Jun 2, 2026 | Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale paramete... |
| CVE-2026-34906 | CRITICAL | 9.3 | 0.6% | Jun 2, 2026 | Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Ex... |
| CVE-2026-10549 | MEDIUM | 5.3 | 0.3% | Jun 2, 2026 | LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede... |
| CVE-2025-53346 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2025-53345 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress ... |
