CVE Vulnerability Database
Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39311 | MEDIUM | 6.8 | 0.3% | May 20, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-39310 | HIGH | 8.6 | 0.4% | May 20, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-35016 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authen... |
| CVE-2026-35015 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows ... |
| CVE-2026-35014 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows aut... |
| CVE-2026-35013 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows a... |
| CVE-2026-35012 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows a... |
| CVE-2026-35011 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authent... |
| CVE-2026-35010 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows au... |
| CVE-2026-35009 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows auth... |
| CVE-2026-35008 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authen... |
| CVE-2026-35007 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows a... |
| CVE-2026-33137 | CRITICAL | 9.3 | 0.6% | May 20, 2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ... |
| CVE-2026-2813 | MEDIUM | 4.1 | 0.3% | May 20, 2026 | ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could e... |
| CVE-2026-2812 | MEDIUM | 5.3 | 0.4% | May 20, 2026 | ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthent... |
| CVE-2026-26028 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Dif... |
| CVE-2026-24218 | HIGH | 8.1 | 0.6% | May 20, 2026 | NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes id... |
| CVE-2026-24217 | HIGH | 8.8 | 0.8% | May 20, 2026 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious ... |
| CVE-2026-24216 | HIGH | 7.8 | 0.3% | May 20, 2026 | NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A succes... |
| CVE-2026-24188 | HIGH | 7.5 | 0.4% | May 20, 2026 | NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of t... |
| CVE-2026-23734 | CRITICAL | 9.3 | 19.5% | May 20, 2026 | XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to ... |
| CVE-2026-30691 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitra... |
| CVE-2026-20240 | MEDIUM | 6.5 | 0.4% | May 20, 2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-20239 | MEDIUM | 6.5 | 0.5% | May 20, 2026 | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.1... |
| CVE-2026-20238 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could a... |
