CVE Vulnerability Database
Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42881 | HIGH | 8.4 | 0.2% | May 14, 2026 | STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve l... |
| CVE-2026-42559 | HIGH | 8.8 | 0.2% | May 14, 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP se... |
| CVE-2026-42457 | CRITICAL | 9 | 0.3% | May 14, 2026 | vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio... |
| CVE-2026-42186 | HIGH | 7.5 | 0.2% | May 14, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace del... |
| CVE-2026-41937 | HIGH | 8.6 | 0.4% | May 14, 2026 | Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_... |
| CVE-2026-41935 | HIGH | 7.1 | 0.3% | May 14, 2026 | Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base:... |
| CVE-2026-41933 | MEDIUM | 6.9 | 0.2% | May 14, 2026 | Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attac... |
| CVE-2026-41932 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::... |
| CVE-2026-24712 | HIGH | 7.3 | 0.9% | May 14, 2026 | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. |
| CVE-2026-24711 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. |
| CVE-2026-24710 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. |
| CVE-2026-21730 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unaut... |
| CVE-2025-69443 | MEDIUM | 6.3 | 0.3% | May 14, 2026 | Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, ru... |
| CVE-2025-62628 | HIGH | 7 | 0.1% | May 14, 2026 | Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali... |
| CVE-2025-62625 | MEDIUM | 6 | 0.2% | May 14, 2026 | Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens... |
| CVE-2025-62619 | MEDIUM | 6.3 | 0.3% | May 14, 2026 | Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex... |
| CVE-2026-6638 | HIGH | 8.8 | 0.2% | May 14, 2026 | SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre... |
| CVE-2026-6637 | HIGH | 8.8 | 0.4% | May 14, 2026 | Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th... |
| CVE-2026-6575 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau... |
| CVE-2026-6479 | HIGH | 7.5 | 0.5% | May 14, 2026 | Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX ... |
| CVE-2026-6478 | MEDIUM | 6.5 | 0.6% | May 14, 2026 | Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us... |
| CVE-2026-6477 | HIGH | 8.8 | 0.5% | May 14, 2026 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee... |
| CVE-2026-6476 | HIGH | 7.2 | 0.3% | May 14, 2026 | SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra... |
| CVE-2026-6475 | HIGH | 8.8 | 0.3% | May 14, 2026 | Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca... |
| CVE-2026-6474 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server... |
