CVE Vulnerability Database
Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39964 | MEDIUM | 5.4 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor t... |
| CVE-2026-9255 | HIGH | 8.4 | 0.1% | May 22, 2026 | Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex... |
| CVE-2026-42626 | MEDIUM | 5.9 | 0.2% | May 22, 2026 | HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD... |
| CVE-2026-37470 | HIGH | 7.3 | 0.3% | May 22, 2026 | An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login p... |
| CVE-2026-36228 | HIGH | 7.3 | 0.4% | May 22, 2026 | Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu... |
| CVE-2026-36227 | MEDIUM | 6.5 | 0.9% | May 22, 2026 | Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and e... |
| CVE-2026-36226 | MEDIUM | 6.1 | 0.3% | May 22, 2026 | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensit... |
| CVE-2026-34207 | HIGH | 7.6 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida... |
| CVE-2026-33712 | CRITICAL | 10 | 0.3% | May 22, 2026 | Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typeb... |
| CVE-2026-32253 | CRITICAL | 9.8 | 0.3% | May 22, 2026 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate a... |
| CVE-2026-28735 | MEDIUM | 5.4 | 0.1% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth... |
| CVE-2026-28445 | HIGH | 8.7 | 0.3% | May 22, 2026 | Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders... |
| CVE-2026-28444 | MEDIUM | 6.5 | 0.3% | May 22, 2026 | Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller ag... |
| CVE-2026-9251 | MEDIUM | 5.4 | 0.1% | May 22, 2026 | Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authentica... |
| CVE-2026-9249 | LOW | 3.1 | 0.1% | May 22, 2026 | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr... |
| CVE-2026-9248 | LOW | 2.6 | 0.1% | May 22, 2026 | Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce... |
| CVE-2026-9247 | LOW | 2.4 | 0.2% | May 22, 2026 | Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi... |
| CVE-2026-9246 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated... |
| CVE-2026-9245 | MEDIUM | 5 | 0.2% | May 22, 2026 | Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated r... |
| CVE-2026-9224 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory ... |
| CVE-2026-9223 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged... |
| CVE-2026-9047 | HIGH | 7.6 | 0.2% | May 22, 2026 | Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows... |
| CVE-2026-8477 | LOW | 2.7 | 0.2% | May 22, 2026 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al... |
| CVE-2026-7325 | HIGH | 7.1 | 0.2% | May 22, 2026 | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authentica... |
| CVE-2026-5171 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access... |
