CVE Vulnerability Database
Search and browse 397,953 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62312 | LOW | 3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic autho... |
| CVE-2025-62311 | MEDIUM | 4.3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. Th... |
| CVE-2025-62310 | MEDIUM | 5.4 | 0.0% | May 14, 2026 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. T... |
| CVE-2025-62309 | LOW | 2.6 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may ... |
| CVE-2025-62308 | MEDIUM | 5.1 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such ... |
| CVE-2025-62305 | MEDIUM | 5.1 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resul... |
| CVE-2026-44504 | HIGH | 8.6 | 0.3% | May 14, 2026 | Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared ... |
| CVE-2026-44503 | HIGH | 7 | 0.5% | May 14, 2026 | The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and othe... |
| CVE-2026-44501 | HIGH | 7.1 | 0.1% | May 14, 2026 | DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize... |
| CVE-2026-42597 | MEDIUM | 5.9 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c... |
| CVE-2026-42596 | CRITICAL | 9.4 | 0.4% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's d... |
| CVE-2026-42595 | HIGH | 8.6 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/f... |
| CVE-2026-42594 | HIGH | 7.5 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine th... |
| CVE-2026-42593 | MEDIUM | 5.3 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff... |
| CVE-2026-42592 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, che... |
| CVE-2026-42591 | HIGH | 8.2 | 0.2% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/... |
| CVE-2026-42590 | HIGH | 8.2 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Got... |
| CVE-2026-42589 | CRITICAL | 9.8 | 2.9% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write... |
| CVE-2026-42283 | HIGH | 7.8 | 0.2% | May 14, 2026 | DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI se... |
| CVE-2026-42281 | HIGH | 8.6 | 1.6% | May 14, 2026 | MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Fo... |
| CVE-2026-42159 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-40893 | HIGH | 8.2 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly ... |
| CVE-2026-44484 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu... |
| CVE-2026-44482 | CRITICAL | 9.6 | 0.3% | May 14, 2026 | soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8... |
| CVE-2026-44375 | HIGH | 7.5 | 0.4% | May 14, 2026 | Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack ... |
