CVE Vulnerability Database
Search and browse 397,857 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48916 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. |
| CVE-2026-48545 | MEDIUM | 6.8 | 0.4% | May 27, 2026 | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa... |
| CVE-2026-48544 | HIGH | 8.7 | 0.4% | May 27, 2026 | Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() metho... |
| CVE-2026-47119 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arb... |
| CVE-2026-47118 | HIGH | 7.1 | 0.4% | May 27, 2026 | Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arb... |
| CVE-2026-45571 | MEDIUM | 5.4 | 0.3% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validat... |
| CVE-2026-45570 | CRITICAL | 9.6 | 0.4% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH t... |
| CVE-2026-45022 | HIGH | 7.5 | 0.2% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may par... |
| CVE-2026-44988 | HIGH | 8.8 | 0.2% | May 27, 2026 | LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding ... |
| CVE-2026-44972 | MEDIUM | 5 | 0.1% | May 27, 2026 | GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled f... |
| CVE-2026-44971 | HIGH | 8.2 | 0.2% | May 27, 2026 | GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scannin... |
| CVE-2026-44902 | HIGH | 7.5 | 0.5% | May 27, 2026 | opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any N... |
| CVE-2026-44839 | MEDIUM | 4.8 | 0.2% | May 27, 2026 | RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1... |
| CVE-2026-44838 | HIGH | 8.1 | 0.3% | May 27, 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level ... |
| CVE-2026-44830 | HIGH | 8.7 | 0.2% | May 27, 2026 | Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when ... |
| CVE-2026-42280 | HIGH | 7.1 | 0.2% | May 27, 2026 | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.j... |
| CVE-2026-42184 | HIGH | 8.8 | 0.3% | May 27, 2026 | Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_loc... |
| CVE-2026-37713 | HIGH | 7.3 | 0.4% | May 27, 2026 | An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary ... |
| CVE-2026-37712 | HIGH | 7.3 | 0.4% | May 27, 2026 | An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary ... |
| CVE-2026-37711 | HIGH | 7.3 | 0.4% | May 27, 2026 | An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary ... |
| CVE-2026-31266 | HIGH | 7.3 | 0.3% | May 27, 2026 | Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate... |
| CVE-2026-30498 | MEDIUM | 6.3 | 0.1% | May 27, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0. |
| CVE-2026-1248 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | IBM Business Automation Workflow containers and traditional may leak information about its database structure in error m... |
| CVE-2025-70103 | HIGH | 7.3 | 0.4% | May 27, 2026 | Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function i... |
| CVE-2026-9704 | HIGH | 8.8 | 0.3% | May 27, 2026 | A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an ove... |
