CVE Vulnerability Database
Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9264 | CRITICAL | 9.3 | 0.2% | May 22, 2026 | A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution an... |
| CVE-2026-34911 | HIGH | 7.7 | 0.7% | May 22, 2026 | A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in Un... |
| CVE-2026-34910 | CRITICAL | 10 | 78.6% | May 22, 2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS ... |
| CVE-2026-34909 | CRITICAL | 10 | 2.3% | May 22, 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a... |
| CVE-2026-34908 | CRITICAL | 10 | 2.5% | May 22, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de... |
| CVE-2026-33000 | CRITICAL | 9.1 | 1.1% | May 22, 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit... |
| CVE-2026-5297 | — | — | — | May 21, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-8435 | MEDIUM | 6.5 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file appr... |
| CVE-2026-8434 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc... |
| CVE-2026-8433 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc... |
| CVE-2026-8432 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star... |
| CVE-2026-8427 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file remo... |
| CVE-2026-8416 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addF... |
| CVE-2026-8415 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/as... |
| CVE-2026-8414 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/dupl... |
| CVE-2026-8413 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/... |
| CVE-2026-8412 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk... |
| CVE-2026-8411 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/... |
| CVE-2026-8410 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/... |
| CVE-2026-8409 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delet... |
| CVE-2026-8337 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in s... |
| CVE-2026-8327 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass... |
| CVE-2026-8245 | MEDIUM | 5.4 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\... |
| CVE-2026-8240 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configur... |
| CVE-2026-8239 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms exist... |
