CVE Vulnerability Database
Search and browse 397,873 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7310 | MEDIUM | 4.4 | 0.1% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ... |
| CVE-2026-48136 | MEDIUM | 4.1 | 4.1% | May 26, 2026 | When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access... |
| CVE-2026-48135 | MEDIUM | 5.3 | 2.6% | May 26, 2026 | A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa... |
| CVE-2026-48134 | MEDIUM | 5.6 | 4.4% | May 26, 2026 | When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific... |
| CVE-2026-48133 | HIGH | 7.5 | 4.8% | May 26, 2026 | When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to r... |
| CVE-2026-48132 | HIGH | 8.1 | 2.1% | May 26, 2026 | The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As... |
| CVE-2026-48131 | HIGH | 8.1 | 2.7% | May 26, 2026 | The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o... |
| CVE-2025-11482 | HIGH | 8.7 | 0.3% | May 26, 2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating Syst... |
| CVE-2026-44410 | LOW | 3.8 | 0.1% | May 26, 2026 | This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended... |
| CVE-2026-39661 | HIGH | 7.5 | 0.4% | May 26, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39642 | MEDIUM | 5.3 | 0.3% | May 26, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code... |
| CVE-2026-27427 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mas... |
| CVE-2026-25713 | HIGH | 7.8 | 0.2% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01)... |
| CVE-2026-25104 | HIGH | 7.8 | 0.2% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01). ... |
| CVE-2026-24638 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-24590 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Config... |
| CVE-2026-8047 | HIGH | 8.7 | 0.4% | May 26, 2026 | The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited ... |
| CVE-2026-8046 | HIGH | 8.1 | 0.3% | May 26, 2026 | The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged ... |
| CVE-2026-44469 | HIGH | 7 | 0.1% | May 26, 2026 | The affected product extracts installation files to a temporary directory with incorrect default permissions during admi... |
| CVE-2026-44468 | HIGH | 8.5 | 0.1% | May 26, 2026 | The affected product creates a directory with insecure default permissions during administrative installation. This allo... |
| CVE-2026-39655 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control... |
| CVE-2026-9534 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cs... |
| CVE-2026-9533 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of th... |
| CVE-2026-9532 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploa... |
| CVE-2026-9496 | HIGH | 7.7 | 0.3% | May 26, 2026 | Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha... |
