CVE Vulnerability Database
Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0243 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attac... |
| CVE-2026-8496 | MEDIUM | 6.1 | 0.4% | May 13, 2026 | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar in... |
| CVE-2026-8466 | HIGH | 8.2 | 0.4% | May 13, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbo... |
| CVE-2026-44248 | HIGH | 7.5 | 0.5% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT ... |
| CVE-2026-43970 | HIGH | 8.2 | 0.5% | May 13, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticate... |
| CVE-2026-42587 | HIGH | 7.5 | 1.0% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpConte... |
| CVE-2026-42586 | HIGH | 7.1 | 0.2% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty... |
| CVE-2026-42585 | HIGH | 7.5 | 0.2% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty inc... |
| CVE-2026-42584 | CRITICAL | 9.1 | 0.8% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClien... |
| CVE-2026-42583 | HIGH | 7.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameD... |
| CVE-2026-42582 | HIGH | 7.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks... |
| CVE-2026-42581 | CRITICAL | 9.8 | 0.6% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjec... |
| CVE-2026-42580 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's c... |
| CVE-2026-42579 | CRITICAL | 9.1 | 1.0% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's D... |
| CVE-2026-42578 | HIGH | 7.5 | 1.1% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's H... |
| CVE-2026-42577 | HIGH | 7.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll t... |
| CVE-2026-42032 | CRITICAL | 9.1 | 0.4% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-42031 | CRITICAL | 9.8 | 1.8% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-41410 | — | — | — | May 13, 2026 | Rejected reason: REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-40520. Reason: This candidate is a dup... |
| CVE-2026-41255 | MEDIUM | 6.1 | 0.1% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-41132 | HIGH | 7.4 | 0.2% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-33585 | LOW | 3.8 | 0.1% | May 13, 2026 | Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke... |
| CVE-2026-33584 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit... |
| CVE-2026-33583 | HIGH | 8.7 | 0.2% | May 13, 2026 | Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a... |
| CVE-2026-30906 | HIGH | 7.8 | 0.1% | May 13, 2026 | Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user t... |
