CVE Vulnerability Database
Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41069 | MEDIUM | 6.5 | 0.3% | May 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file... |
| CVE-2026-40864 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through ... |
| CVE-2026-3294 | HIGH | 8.8 | 0.4% | May 22, 2026 | An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac... |
| CVE-2026-5843 | HIGH | 8.6 | 0.2% | May 22, 2026 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and exe... |
| CVE-2026-5817 | HIGH | 8.6 | 0.2% | May 22, 2026 | The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loadin... |
| CVE-2026-40610 | MEDIUM | 5.5 | 0.3% | May 22, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1... |
| CVE-2026-40607 | HIGH | 7.5 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerabi... |
| CVE-2026-40598 | MEDIUM | 6.9 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the re... |
| CVE-2026-40597 | HIGH | 7.6 | 0.5% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS ... |
| CVE-2026-40596 | HIGH | 7.2 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated us... |
| CVE-2026-40295 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module... |
| CVE-2026-39824 | LOW | 3.3 | 0.1% | May 22, 2026 | NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum siz... |
| CVE-2026-9291 | HIGH | 7.5 | 0.4% | May 22, 2026 | Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot... |
| CVE-2026-6406 | HIGH | 8.8 | 0.2% | May 22, 2026 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When EC... |
| CVE-2026-48700 | CRITICAL | 9.3 | 0.2% | May 22, 2026 | An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI... |
| CVE-2026-40172 | HIGH | 8.1 | 0.5% | May 22, 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT... |
| CVE-2026-40166 | HIGH | 7.1 | 0.5% | May 22, 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent... |
| CVE-2026-39970 | HIGH | 8.5 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.type... |
| CVE-2026-39969 | MEDIUM | 6.5 | 0.1% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/works... |
| CVE-2026-39968 | HIGH | 7.1 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via ... |
| CVE-2026-39967 | LOW | 3.1 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r... |
| CVE-2026-39966 | MEDIUM | 6.5 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions t... |
| CVE-2026-46727 | HIGH | 8.1 | 0.5% | May 22, 2026 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getadd... |
| CVE-2026-42627 | MEDIUM | 6.2 | 0.1% | May 22, 2026 | In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a craft... |
| CVE-2026-39965 | HIGH | 7.7 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques... |
