CVE Vulnerability Database
Search and browse 397,933 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8952 | HIGH | 8.8 | 0.4% | May 19, 2026 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 15... |
| CVE-2026-8951 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151. |
| CVE-2026-8950 | CRITICAL | 9.3 | 0.2% | May 19, 2026 | Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14... |
| CVE-2026-8949 | HIGH | 7.5 | 0.6% | May 19, 2026 | Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunde... |
| CVE-2026-8948 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird ... |
| CVE-2026-8947 | HIGH | 7.3 | 0.4% | May 19, 2026 | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36,... |
| CVE-2026-8946 | HIGH | 7.5 | 0.6% | May 19, 2026 | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Fir... |
| CVE-2026-8945 | HIGH | 7.5 | 0.4% | May 19, 2026 | Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. |
| CVE-2026-6354 | — | — | — | May 19, 2026 | Rejected reason: Voluntarily withdrawn |
| CVE-2026-47323 | CRITICAL | 9.8 | 1.4% | May 19, 2026 | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra... |
| CVE-2026-43633 | CRITICAL | 10 | 1.1% | May 19, 2026 | HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a ... |
| CVE-2026-42100 | HIGH | 7.5 | 0.7% | May 19, 2026 | Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to ... |
| CVE-2026-42099 | HIGH | 7.5 | 0.7% | May 19, 2026 | Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The applica... |
| CVE-2026-42098 | HIGH | 8.7 | 0.4% | May 19, 2026 | Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An... |
| CVE-2026-42097 | HIGH | 8.8 | 0.9% | May 19, 2026 | Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter ... |
| CVE-2026-42096 | HIGH | 8.8 | 0.6% | May 19, 2026 | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per... |
| CVE-2026-23558 | HIGH | 7.8 | 0.1% | May 19, 2026 | The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ... |
| CVE-2026-23557 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri... |
| CVE-2025-40904 | MEDIUM | 5.4 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an... |
| CVE-2025-40903 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid... |
| CVE-2025-40902 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p... |
| CVE-2025-40901 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation... |
| CVE-2025-40900 | MEDIUM | 5.1 | 0.2% | May 19, 2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an... |
| CVE-2025-14575 | LOW | 1.8 | 0.1% | May 19, 2026 | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (... |
| CVE-2026-8912 | HIGH | 7.5 | 0.4% | May 19, 2026 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to... |
