CVE Vulnerability Database
Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41281 | MEDIUM | 6.3 | 0.1% | May 14, 2026 | Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CW... |
| CVE-2026-8500 | CRITICAL | 9.8 | 1.7% | May 13, 2026 | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing ht... |
| CVE-2026-32991 | HIGH | 7.1 | 0.2% | May 13, 2026 | Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner ac... |
| CVE-2026-29206 | HIGH | 8.1 | 0.3% | May 13, 2026 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the roo... |
| CVE-2026-45158 | CRITICAL | 9.1 | 0.5% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP... |
| CVE-2026-44478 | HIGH | 7.5 | 0.2% | May 13, 2026 | hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the una... |
| CVE-2026-44471 | HIGH | 7.8 | 0.2% | May 13, 2026 | gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, wh... |
| CVE-2026-44448 | MEDIUM | 6.5 | 0.1% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints fa... |
| CVE-2026-44447 | HIGH | 7.5 | 0.3% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to ... |
| CVE-2026-44446 | HIGH | 7.5 | 0.3% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were ... |
| CVE-2026-44445 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restrict... |
| CVE-2026-44442 | CRITICAL | 9.9 | 0.3% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforc... |
| CVE-2026-44441 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user cou... |
| CVE-2026-44440 | MEDIUM | 5.7 | 0.4% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitati... |
| CVE-2026-44439 | HIGH | 7.5 | 0.3% | May 13, 2026 | PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not suffic... |
| CVE-2026-44437 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25,... |
| CVE-2026-44426 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — ... |
| CVE-2026-44425 | MEDIUM | 5.4 | 0.3% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in ... |
| CVE-2026-44424 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever th... |
| CVE-2026-44423 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any a... |
| CVE-2026-44369 | HIGH | 8.5 | 0.3% | May 13, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacke... |
| CVE-2026-44195 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler... |
| CVE-2026-44194 | CRITICAL | 9.1 | 6.4% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE)... |
| CVE-2026-44193 | CRITICAL | 9.1 | 0.7% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_se... |
| CVE-2026-42463 | HIGH | 8.1 | 0.2% | May 13, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr... |
