CVE Vulnerability Database
Search and browse 397,845 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10074 | MEDIUM | 6.9 | 0.3% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo... |
| CVE-2026-10073 | HIGH | 8.7 | 0.4% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to ... |
| CVE-2026-10072 | HIGH | 8.6 | 0.5% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up... |
| CVE-2026-10061 | CRITICAL | 9.8 | 5.0% | May 29, 2026 | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. ... |
| CVE-2026-10060 | CRITICAL | 9.8 | 5.0% | May 29, 2026 | A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor... |
| CVE-2026-9509 | HIGH | 8.7 | 0.4% | May 29, 2026 | An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated... |
| CVE-2026-9508 | CRITICAL | 10 | 0.3% | May 29, 2026 | Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow bac... |
| CVE-2026-8326 | CRITICAL | 10 | 0.4% | May 29, 2026 | Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitra... |
| CVE-2026-49324 | MEDIUM | 4.6 | 0.2% | May 29, 2026 | Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025... |
| CVE-2026-49323 | MEDIUM | 4.3 | 0.1% | May 29, 2026 | Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcyc... |
| CVE-2026-48527 | HIGH | 8.7 | 0.2% | May 29, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by... |
| CVE-2026-45611 | — | — | — | May 29, 2026 | Rejected reason: Further research determined the issue is not a vulnerability. |
| CVE-2026-45551 | MEDIUM | 5.1 | 0.2% | May 29, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.1... |
| CVE-2026-45312 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injectio... |
| CVE-2026-45043 | CRITICAL | 9.3 | 0.2% | May 29, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rust... |
| CVE-2026-10071 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers ... |
| CVE-2026-9811 | MEDIUM | 5.4 | 0.1% | May 29, 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s... |
| CVE-2026-9809 | HIGH | 7.6 | 0.2% | May 29, 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project ... |
| CVE-2026-9808 | HIGH | 7.1 | 0.2% | May 29, 2026 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain co... |
| CVE-2026-9559 | CRITICAL | 9.9 | 0.6% | May 29, 2026 | A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur... |
| CVE-2025-41281 | HIGH | 7.8 | 0.5% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41280 | HIGH | 7.8 | 0.1% | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.... |
| CVE-2025-41279 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41278 | HIGH | 7.8 | 0.1% | May 29, 2026 | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R260114104... |
| CVE-2025-41277 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
