CVE Vulnerability Database
Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8370 | HIGH | 8.5 | 0.1% | May 19, 2026 | Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power ... |
| CVE-2026-8096 | MEDIUM | 6.5 | 0.4% | May 19, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa... |
| CVE-2026-8073 | HIGH | 7.5 | 0.6% | May 19, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del... |
| CVE-2026-41470 | HIGH | 8.2 | 0.5% | May 19, 2026 | LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at... |
| CVE-2026-34154 | MEDIUM | 5.3 | 0.2% | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1... |
| CVE-2026-33741 | MEDIUM | 6.8 | 0.2% | May 19, 2026 | EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use... |
| CVE-2026-33642 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit... |
| CVE-2026-33637 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 ... |
| CVE-2026-32738 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen... |
| CVE-2026-8605 | CRITICAL | 9.8 | 0.4% | May 19, 2026 | In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA syst... |
| CVE-2026-8604 | HIGH | 8.8 | 0.2% | May 19, 2026 | In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a vic... |
| CVE-2026-8603 | CRITICAL | 9.8 | 1.3% | May 19, 2026 | In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on t... |
| CVE-2026-8602 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at... |
| CVE-2026-6009 | HIGH | 8.7 | 0.5% | May 19, 2026 | Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow... |
| CVE-2026-47107 | HIGH | 8.6 | 0.2% | May 19, 2026 | Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files ... |
| CVE-2026-33633 | HIGH | 8.8 | 0.4% | May 19, 2026 | Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_dat... |
| CVE-2026-32134 | MEDIUM | 5.9 | 0.4% | May 19, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles... |
| CVE-2025-61081 | — | — | — | May 19, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-5511 | LOW | 2.7 | 0.2% | May 19, 2026 | In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i... |
| CVE-2026-47358 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded... |
| CVE-2026-47357 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem... |
| CVE-2026-47356 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the fi... |
| CVE-2026-36829 | CRITICAL | 9.8 | 1.3% | May 19, 2026 | An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7.... |
| CVE-2026-36828 | HIGH | 8.8 | 1.7% | May 19, 2026 | A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includin... |
| CVE-2026-36827 | MEDIUM | 5.4 | 0.7% | May 19, 2026 | A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface inv... |
