CVE Vulnerability Database
Search and browse 397,870 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25900 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the feed modules. |
| CVE-2026-24212 | CRITICAL | 9.8 | 0.7% | May 26, 2026 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A s... |
| CVE-2026-24162 | HIGH | 7.8 | 0.4% | May 26, 2026 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of unt... |
| CVE-2025-36221 | HIGH | 7.5 | 0.3% | May 26, 2026 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default pas... |
| CVE-2025-36220 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to... |
| CVE-2025-36148 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transacti... |
| CVE-2025-36145 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could... |
| CVE-2025-36126 | HIGH | 7.6 | 0.2% | May 26, 2026 | IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to store... |
| CVE-2025-14290 | MEDIUM | 5.4 | 0.2% | May 26, 2026 | IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM... |
| CVE-2025-13755 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) store... |
| CVE-2026-48692 | HIGH | 8.1 | 0.2% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The... |
| CVE-2026-48688 | HIGH | 7.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute... |
| CVE-2026-48687 | CRITICAL | 9.8 | 1.6% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integrat... |
| CVE-2026-48686 | CRITICAL | 9.8 | 0.6% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachab... |
| CVE-2026-48685 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attrib... |
| CVE-2026-48684 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In ... |
| CVE-2026-48683 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset p... |
| CVE-2026-46620 | MEDIUM | 6.5 | 0.1% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on c... |
| CVE-2026-43936 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of... |
| CVE-2026-43935 | HIGH | 8.1 | 0.3% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p... |
| CVE-2026-43934 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the applicati... |
| CVE-2026-40564 | MEDIUM | 6.5 | 0.5% | May 26, 2026 | Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Ku... |
| CVE-2026-38587 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw ex... |
| CVE-2026-25112 | HIGH | 7.8 | 0.1% | May 26, 2026 | A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack. |
| CVE-2026-9552 | HIGH | 7.3 | 0.3% | May 26, 2026 | A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown c... |
