CVE Vulnerability Database
Search and browse 397,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8695 | CRITICAL | 9.8 | 0.6% | May 15, 2026 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers t... |
| CVE-2026-46383 | MEDIUM | 5.5 | 0.6% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM conta... |
| CVE-2026-45539 | HIGH | 7.4 | 0.7% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive ... |
| CVE-2026-45038 | HIGH | 7.8 | 0.2% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape cont... |
| CVE-2026-45037 | HIGH | 7.1 | 0.1% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe... |
| CVE-2026-45036 | HIGH | 7 | 0.1% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatical... |
| CVE-2026-45035 | HIGH | 8.8 | 0.4% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the ha... |
| CVE-2026-44774 | CRITICAL | 9.9 | 0.5% | May 15, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP... |
| CVE-2026-44717 | CRITICAL | 9.8 | 0.5% | May 15, 2026 | MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the ... |
| CVE-2026-44714 | HIGH | 7.5 | 0.3% | May 15, 2026 | The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends(... |
| CVE-2026-44699 | CRITICAL | 9.1 | 0.2% | May 15, 2026 | LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parame... |
| CVE-2026-44641 | HIGH | 7.1 | 0.4% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma... |
| CVE-2026-44310 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0... |
| CVE-2026-44309 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsi... |
| CVE-2026-42458 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-42207 | MEDIUM | 6.1 | 0.1% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-42155 | CRITICAL | 9.3 | 0.3% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-41258 | CRITICAL | 9.1 | 0.3% | May 15, 2026 | OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptRe... |
| CVE-2026-41181 | MEDIUM | 5.8 | 0.4% | May 15, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information di... |
| CVE-2026-23695 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in t... |
| CVE-2026-46508 | HIGH | 7.8 | 0.2% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo ... |
| CVE-2026-45803 | LOW | 3.5 | 0.2% | May 15, 2026 | `gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i... |
| CVE-2026-45773 | MEDIUM | 6.5 | 0.1% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-... |
| CVE-2026-45772 | CRITICAL | 9.8 | 0.4% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turbo... |
| CVE-2026-35194 | HIGH | 8.1 | 0.4% | May 15, 2026 | Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated u... |
