CVE Vulnerability Database
Search and browse 397,953 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6646 | MEDIUM | 6.4 | 0.3% | May 15, 2026 | The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v... |
| CVE-2026-4094 | HIGH | 8.1 | 0.3% | May 15, 2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du... |
| CVE-2026-41702 | HIGH | 7 | 0.1% | May 15, 2026 | VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a... |
| CVE-2026-43490 | HIGH | 8.8 | 0.4% | May 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inher... |
| CVE-2026-28761 | HIGH | 8.5 | 0.1% | May 15, 2026 | Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a... |
| CVE-2026-24662 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and ear... |
| CVE-2026-0481 | CRITICAL | 9.2 | 0.3% | May 15, 2026 | Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per... |
| CVE-2025-54518 | HIGH | 7 | 0.3% | May 15, 2026 | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to... |
| CVE-2025-52532 | LOW | 2 | 0.1% | May 15, 2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa... |
| CVE-2024-36334 | HIGH | 7 | 0.1% | May 15, 2026 | Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta... |
| CVE-2024-36333 | HIGH | 7.8 | 0.1% | May 15, 2026 | A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti... |
| CVE-2024-36323 | HIGH | 8.8 | 0.1% | May 15, 2026 | Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf... |
| CVE-2024-21950 | LOW | 1.8 | 0.1% | May 15, 2026 | An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memo... |
| CVE-2026-7373 | HIGH | 8.5 | 0.2% | May 15, 2026 | Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr... |
| CVE-2026-2652 | HIGH | 8.6 | 1.5% | May 15, 2026 | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when... |
| CVE-2026-0428 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2026-0427 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt... |
| CVE-2025-66664 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf... |
| CVE-2025-66660 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2025-54517 | HIGH | 8.5 | 0.1% | May 15, 2026 | Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem... |
| CVE-2025-54511 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp... |
| CVE-2025-48516 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc... |
| CVE-2025-48513 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini... |
| CVE-2025-29944 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p... |
| CVE-2025-29938 | HIGH | 7.1 | 0.1% | May 15, 2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi... |
