CVE Vulnerability Database
Search and browse 397,840 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48555 | HIGH | 7.4 | 0.2% | May 29, 2026 | Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows rem... |
| CVE-2026-47266 | HIGH | 8.7 | 0.3% | May 29, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing... |
| CVE-2026-47123 | HIGH | 7.5 | 0.1% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processin... |
| CVE-2026-46599 | HIGH | 7.5 | 0.4% | May 29, 2026 | The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit... |
| CVE-2026-46527 | HIGH | 7.5 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has c... |
| CVE-2026-46385 | HIGH | 7.5 | 0.6% | May 29, 2026 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-contro... |
| CVE-2026-46384 | HIGH | 7.5 | 0.5% | May 29, 2026 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit val... |
| CVE-2026-45700 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an... |
| CVE-2026-45697 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted ... |
| CVE-2026-45613 | LOW | 3.3 | 0.1% | May 29, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bi... |
| CVE-2026-45372 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's se... |
| CVE-2026-45352 | HIGH | 7.5 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i... |
| CVE-2026-45324 | LOW | 3.3 | 0.1% | May 29, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm... |
| CVE-2026-45294 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset ... |
| CVE-2026-45151 | LOW | 2.9 | 0.2% | May 29, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can derefe... |
| CVE-2026-45149 | HIGH | 7.5 | 0.3% | May 29, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.... |
| CVE-2026-44640 | MEDIUM | 4.5 | 0.1% | May 29, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_... |
| CVE-2026-44422 | HIGH | 8.8 | 0.4% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts on... |
| CVE-2026-44421 | HIGH | 8.8 | 0.5% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a h... |
| CVE-2026-44420 | HIGH | 8.8 | 3.7% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a h... |
| CVE-2026-44287 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/... |
| CVE-2026-44285 | HIGH | 7.7 | 0.3% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo... |
| CVE-2026-42500 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid ... |
| CVE-2026-34127 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG... |
| CVE-2026-9051 | CRITICAL | 9.3 | 0.6% | May 29, 2026 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an ... |
