CVE Vulnerability Database
Search and browse 397,836 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45278 | MEDIUM | 6.1 | 0.2% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can ... |
| CVE-2026-45277 | LOW | 3.3 | 0.1% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arb... |
| CVE-2026-45275 | MEDIUM | 6.5 | 0.4% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability... |
| CVE-2026-43958 | HIGH | 7.8 | 0.2% | Jun 1, 2026 | A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a ... |
| CVE-2026-43625 | HIGH | 8.2 | 0.2% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo... |
| CVE-2026-43624 | HIGH | 8.8 | 0.4% | Jun 1, 2026 | F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauth... |
| CVE-2026-43623 | HIGH | 8.8 | 0.3% | Jun 1, 2026 | microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/micro... |
| CVE-2026-41013 | HIGH | 8.1 | 0.2% | Jun 1, 2026 | Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF s... |
| CVE-2026-40990 | MEDIUM | 6.5 | 0.2% | Jun 1, 2026 | OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc... |
| CVE-2026-40989 | MEDIUM | 6.5 | 0.2% | Jun 1, 2026 | Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi... |
| CVE-2026-37235 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. T... |
| CVE-2026-37233 | HIGH | 7.5 | 0.5% | Jun 1, 2026 | FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ri... |
| CVE-2026-37232 | HIGH | 8.6 | 0.4% | Jun 1, 2026 | An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric... |
| CVE-2026-37231 | HIGH | 7.5 | 0.5% | Jun 1, 2026 | FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,... |
| CVE-2026-37230 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in ... |
| CVE-2026-37229 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote una... |
| CVE-2026-37228 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a f... |
| CVE-2026-37226 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lo... |
| CVE-2026-30963 | LOW | 2.7 | 0.2% | Jun 1, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved thr... |
| CVE-2026-23638 | MEDIUM | 6.5 | 0.2% | Jun 1, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil... |
| CVE-2026-22872 | CRITICAL | 9.1 | 0.4% | Jun 1, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin pri... |
| CVE-2026-10283 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti... |
| CVE-2026-10282 | MEDIUM | 5.3 | 0.2% | Jun 1, 2026 | A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi... |
| CVE-2026-10281 | HIGH | 7.3 | 0.4% | Jun 1, 2026 | A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of th... |
| CVE-2026-10280 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file... |
