CVE Vulnerability Database
Search and browse 397,819 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48570 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to... |
| CVE-2025-32348 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead... |
| CVE-2025-26418 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when ... |
| CVE-2025-22426 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in th... |
| CVE-2025-22424 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul... |
| CVE-2019-25716 | HIGH | 7.5 | 0.4% | Jun 1, 2026 | Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote... |
| CVE-2018-25435 | MEDIUM | 6.9 | 0.2% | Jun 1, 2026 | ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions o... |
| CVE-2018-25434 | HIGH | 8.8 | 0.3% | Jun 1, 2026 | WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S... |
| CVE-2018-25433 | HIGH | 8.8 | 0.3% | Jun 1, 2026 | Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to e... |
| CVE-2018-25432 | HIGH | 8.6 | 0.2% | Jun 1, 2026 | Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwri... |
| CVE-2018-25431 | HIGH | 7.1 | 0.3% | Jun 1, 2026 | No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint tha... |
| CVE-2018-25430 | HIGH | 7.1 | 0.3% | Jun 1, 2026 | Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que... |
| CVE-2018-25429 | HIGH | 7.1 | 0.3% | Jun 1, 2026 | Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que... |
| CVE-2018-25428 | HIGH | 8.8 | 0.3% | Jun 1, 2026 | Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q... |
| CVE-2018-25427 | CRITICAL | 9.8 | 0.9% | Jun 1, 2026 | Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary co... |
| CVE-2026-5419 | LOW | 3.7 | 0.4% | Jun 1, 2026 | A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing si... |
| CVE-2026-49433 | MEDIUM | 5 | 0.1% | Jun 1, 2026 | The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an ... |
| CVE-2026-49140 | MEDIUM | 5.3 | 0.3% | Jun 1, 2026 | Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler t... |
| CVE-2026-49139 | HIGH | 7 | 0.4% | Jun 1, 2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handl... |
| CVE-2026-49138 | MEDIUM | 5.3 | 0.3% | Jun 1, 2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows re... |
| CVE-2026-49136 | HIGH | 8.7 | 0.4% | Jun 1, 2026 | Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() ... |
| CVE-2026-49135 | HIGH | 7.2 | 0.1% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces... |
| CVE-2026-49134 | HIGH | 7.5 | 0.3% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers ... |
| CVE-2026-37234 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disc... |
| CVE-2026-24751 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat... |
