CVE Vulnerability Database
Search and browse 397,870 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9551 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of ... |
| CVE-2026-9550 | HIGH | 7.3 | 0.5% | May 26, 2026 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0.... |
| CVE-2026-4480 | CRITICAL | 9 | 13.9% | May 26, 2026 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the comma... |
| CVE-2026-46368 | HIGH | 8.8 | 6.6% | May 26, 2026 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distribu... |
| CVE-2026-45247 | CRITICAL | 9.8 | 27.5% | May 26, 2026 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that ... |
| CVE-2026-45082 | HIGH | 7.6 | 0.3% | May 26, 2026 | Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability... |
| CVE-2026-43919 | — | — | — | May 26, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a ... |
| CVE-2026-42785 | HIGH | 8.6 | 0.7% | May 26, 2026 | OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitra... |
| CVE-2026-42425 | HIGH | 8.6 | 0.6% | May 26, 2026 | OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to exe... |
| CVE-2026-42347 | — | — | — | May 26, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason: This candidate is a ... |
| CVE-2026-41917 | MEDIUM | 6.9 | 0.4% | May 26, 2026 | OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin... |
| CVE-2026-41401 | HIGH | 7.1 | 0.5% | May 26, 2026 | libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly up... |
| CVE-2026-40034 | HIGH | 8.5 | 0.4% | May 26, 2026 | gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmo... |
| CVE-2026-40033 | HIGH | 8.8 | 0.9% | May 26, 2026 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers t... |
| CVE-2026-9544 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by thi... |
| CVE-2026-9543 | CRITICAL | 9.8 | 2.1% | May 26, 2026 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the fi... |
| CVE-2026-9542 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of ... |
| CVE-2026-9541 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqob... |
| CVE-2026-9540 | MEDIUM | 5.5 | 0.4% | May 26, 2026 | A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component ... |
| CVE-2026-8479 | MEDIUM | 6.9 | 0.2% | May 26, 2026 | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially craf... |
| CVE-2026-8174 | MEDIUM | 5.7 | 0.4% | May 26, 2026 | Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo... |
| CVE-2026-7374 | CRITICAL | 9.9 | 0.7% | May 26, 2026 | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with ed... |
| CVE-2026-7310 | MEDIUM | 4.4 | 0.1% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ... |
| CVE-2026-48136 | MEDIUM | 4.1 | 4.1% | May 26, 2026 | When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access... |
| CVE-2026-48135 | MEDIUM | 5.3 | 2.6% | May 26, 2026 | A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa... |
