CVE Vulnerability Database
Search and browse 397,845 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41276 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41275 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41274 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41273 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI... |
| CVE-2025-41272 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41271 | HIGH | 7.5 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hos... |
| CVE-2025-41270 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41269 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41268 | CRITICAL | 9.1 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and... |
| CVE-2025-41267 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41266 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41265 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2026-9558 | CRITICAL | 9.9 | 0.4% | May 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi... |
| CVE-2026-9557 | MEDIUM | 6.4 | 0.1% | May 29, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of... |
| CVE-2026-49201 | CRITICAL | 9.8 | 0.3% | May 29, 2026 | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows a... |
| CVE-2026-46579 | HIGH | 7.5 | 0.4% | May 29, 2026 | A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP fronte... |
| CVE-2026-42965 | MEDIUM | 6.5 | 0.3% | May 29, 2026 | A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creat... |
| CVE-2026-10078 | LOW | 2.7 | 0.2% | May 29, 2026 | A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec... |
| CVE-2025-12714 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due ... |
| CVE-2026-9189 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verifi... |
| CVE-2026-6075 | HIGH | 8.1 | 0.2% | May 29, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2026-49200 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file conta... |
| CVE-2026-49199 | CRITICAL | 9.8 | 1.3% | May 29, 2026 | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. |
| CVE-2026-49198 | MEDIUM | 4.9 | 0.2% | May 29, 2026 | Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize... |
| CVE-2026-49197 | CRITICAL | 9.8 | 0.3% | May 29, 2026 | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ... |
