CVE Vulnerability Database
Search and browse 397,909 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48229 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows auth... |
| CVE-2026-48228 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows aut... |
| CVE-2026-48227 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authe... |
| CVE-2026-48226 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows auth... |
| CVE-2026-48225 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authent... |
| CVE-2026-48224 | MEDIUM | 5.4 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authen... |
| CVE-2026-48223 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows auth... |
| CVE-2026-48222 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authen... |
| CVE-2026-48221 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authe... |
| CVE-2026-48220 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authen... |
| CVE-2026-48219 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authen... |
| CVE-2026-48218 | MEDIUM | 5.4 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that ... |
| CVE-2026-48217 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows... |
| CVE-2026-48216 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows aut... |
| CVE-2026-48215 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authen... |
| CVE-2026-48214 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authen... |
| CVE-2026-39593 | MEDIUM | 6.5 | 0.3% | May 21, 2026 | Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2026-48213 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authentic... |
| CVE-2026-48207 | CRITICAL | 9.8 | 0.6% | May 21, 2026 | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented Deserializati... |
| CVE-2026-9089 | HIGH | 8.8 | 0.3% | May 21, 2026 | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and ... |
| CVE-2026-39531 | CRITICAL | 9.3 | 0.2% | May 21, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W... |
| CVE-2026-36189 | MEDIUM | 6.2 | 0.1% | May 21, 2026 | Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e... |
| CVE-2026-1816 | MEDIUM | 6.3 | 0.2% | May 21, 2026 | Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation ... |
| CVE-2026-1815 | MEDIUM | 5.7 | 0.2% | May 21, 2026 | Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application... |
| CVE-2026-45208 | HIGH | 7.8 | 0.3% | May 21, 2026 | A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges ... |
