CVE Vulnerability Database
Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42506 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-42502 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-39821 | CRITICAL | 9.6 | 0.7% | May 22, 2026 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For e... |
| CVE-2026-27136 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-25681 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-25680 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. |
| CVE-2022-34363 | HIGH | 7.5 | 0.2% | May 22, 2026 | Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisp... |
| CVE-2022-31231 | HIGH | 7.5 | 0.3% | May 22, 2026 | Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A... |
| CVE-2026-9256 | HIGH | 8.1 | 10.0% | May 22, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w... |
| CVE-2026-8992 | HIGH | 8.8 | 0.6% | May 22, 2026 | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenti... |
| CVE-2026-8353 | MEDIUM | 4.8 | 0.1% | May 22, 2026 | Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inje... |
| CVE-2026-8347 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog... |
| CVE-2026-8340 | MEDIUM | 4.3 | 0.1% | May 22, 2026 | Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm... |
| CVE-2025-46371 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability ... |
| CVE-2025-45145 | HIGH | 7.5 | 0.7% | May 22, 2026 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attac... |
| CVE-2025-32751 | MEDIUM | 5.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low... |
| CVE-2021-21508 | MEDIUM | 6.7 | 0.1% | May 22, 2026 | Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin u... |
| CVE-2026-9277 | HIGH | 8.1 | 0.8% | May 22, 2026 | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The ... |
| CVE-2026-8997 | MEDIUM | 4.8 | 0.1% | May 22, 2026 | vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)... |
| CVE-2026-8673 | CRITICAL | 9.1 | 0.2% | May 22, 2026 | Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Atta... |
| CVE-2026-8672 | MEDIUM | 5.1 | 0.1% | May 22, 2026 | Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User... |
| CVE-2026-8671 | HIGH | 7.5 | 0.2% | May 22, 2026 | Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows R... |
| CVE-2026-8670 | CRITICAL | 9.6 | 0.2% | May 22, 2026 | Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session ID... |
| CVE-2025-32749 | HIGH | 7.5 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit... |
| CVE-2025-32747 | HIGH | 7.8 | 0.1% | May 22, 2026 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged... |
