CVE Vulnerability Database
Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6898 | HIGH | 8.8 | 0.2% | May 23, 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-6897 | HIGH | 8.8 | 0.2% | May 23, 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-6895 | HIGH | 8.8 | 0.2% | May 23, 2026 | The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclos... |
| CVE-2026-6419 | HIGH | 8.8 | 0.3% | May 23, 2026 | The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up ... |
| CVE-2026-47280 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-45659 | HIGH | 8.8 | 3.2% | May 22, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2026-42901 | CRITICAL | 10 | 0.3% | May 22, 2026 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-42827 | HIGH | 7.5 | 0.5% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-41149 | MEDIUM | 5.3 | 0.4% | May 22, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ... |
| CVE-2026-41148 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ... |
| CVE-2026-41104 | HIGH | 7.5 | 0.9% | May 22, 2026 | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform... |
| CVE-2026-41090 | CRITICAL | 9.3 | 0.4% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-40412 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code ... |
| CVE-2026-40411 | HIGH | 8.8 | 0.5% | May 22, 2026 | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. |
| CVE-2026-35430 | HIGH | 8.8 | 0.4% | May 22, 2026 | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized atta... |
| CVE-2026-33843 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized ... |
| CVE-2026-26147 | HIGH | 7.7 | 0.6% | May 22, 2026 | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. |
| CVE-2026-23663 | HIGH | 7.5 | 0.6% | May 22, 2026 | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-23652 | CRITICAL | 9.8 | 0.6% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an u... |
| CVE-2026-41147 | HIGH | 8.7 | 0.3% | May 22, 2026 | NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS)... |
| CVE-2026-41076 | HIGH | 8.1 | 0.4% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 t... |
| CVE-2026-41075 | HIGH | 8.8 | 0.3% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through ... |
| CVE-2026-41074 | HIGH | 7.1 | 0.1% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Si... |
| CVE-2026-41073 | MEDIUM | 4.6 | 0.2% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.... |
| CVE-2026-41071 | HIGH | 8.1 | 0.3% | May 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w... |
