CVE Vulnerability Database
Search and browse 397,953 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42572 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a... |
| CVE-2026-42334 | HIGH | 7.5 | 0.3% | May 14, 2026 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22... |
| CVE-2026-41888 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELE... |
| CVE-2026-41615 | HIGH | 7.4 | 0.6% | May 14, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to... |
| CVE-2025-15024 | HIGH | 8.8 | 0.2% | May 14, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Tra... |
| CVE-2025-15023 | HIGH | 8.8 | 0.2% | May 14, 2026 | Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Indus... |
| CVE-2026-7805 | — | — | — | May 14, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-3258. Reason: This candidate is a r... |
| CVE-2026-6923 | LOW | 3.8 | 0.1% | May 14, 2026 | A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie... |
| CVE-2026-45448 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | CWE-601 URL redirection to untrusted site ('open redirect') |
| CVE-2026-44827 | HIGH | 8.8 | 0.6% | May 14, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execut... |
| CVE-2026-44516 | HIGH | 7.6 | 0.2% | May 14, 2026 | Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClien... |
| CVE-2026-44515 | LOW | 2.3 | 0.2% | May 14, 2026 | Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed... |
| CVE-2026-44514 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoi... |
| CVE-2026-44513 | HIGH | 8.8 | 1.1% | May 14, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPip... |
| CVE-2026-44511 | HIGH | 7.4 | 0.2% | May 14, 2026 | Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies wer... |
| CVE-2026-44348 | LOW | 2.5 | 0.1% | May 14, 2026 | PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha... |
| CVE-2026-44312 | MEDIUM | 5.8 | 0.1% | May 14, 2026 | css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allo... |
| CVE-2026-42555 | CRITICAL | 9.1 | 0.6% | May 14, 2026 | Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32... |
| CVE-2026-20224 | HIGH | 8.6 | 0.7% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated,... |
| CVE-2026-20210 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-20209 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-20182 | CRITICAL | 10 | 87.7% | May 14, 2026 | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fi... |
| CVE-2025-62317 | LOW | 2.6 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive... |
| CVE-2025-62316 | LOW | 2.3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured... |
| CVE-2025-62313 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m... |
