CVE Vulnerability Database
Search and browse 397,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39803 | HIGH | 7.5 | 0.6% | May 13, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia... |
| CVE-2026-37430 | HIGH | 7.3 | 0.3% | May 13, 2026 | An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allow... |
| CVE-2026-37429 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU... |
| CVE-2026-37428 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD... |
| CVE-2026-6177 | HIGH | 7.2 | 0.5% | May 13, 2026 | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi... |
| CVE-2026-42961 | MEDIUM | 5.1 | 0.2% | May 13, 2026 | ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token... |
| CVE-2026-42950 | MEDIUM | 5.1 | 0.2% | May 13, 2026 | ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a ... |
| CVE-2026-42948 | MEDIUM | 4.8 | 0.2% | May 13, 2026 | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrato... |
| CVE-2026-42062 | CRITICAL | 9.8 | 1.6% | May 13, 2026 | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If process... |
| CVE-2026-40621 | CRITICAL | 9.8 | 0.5% | May 13, 2026 | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected produc... |
| CVE-2026-3426 | MEDIUM | 4.3 | 0.3% | May 13, 2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c... |
| CVE-2026-3425 | HIGH | 8.8 | 0.6% | May 13, 2026 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2026-35506 | HIGH | 8.6 | 1.3% | May 13, 2026 | ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr par... |
| CVE-2026-25107 | MEDIUM | 6.9 | 0.1% | May 13, 2026 | ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files... |
| CVE-2026-7168 | MEDIUM | 5.3 | 0.5% | May 13, 2026 | Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and the... |
| CVE-2026-7009 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify t... |
| CVE-2026-6429 | MEDIUM | 5.3 | 0.5% | May 13, 2026 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password use... |
| CVE-2026-6276 | HIGH | 7.5 | 0.3% | May 13, 2026 | Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done u... |
| CVE-2026-6253 | MEDIUM | 5.9 | 0.7% | May 13, 2026 | curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond... |
| CVE-2026-5773 | HIGH | 7.5 | 0.6% | May 13, 2026 | libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent ... |
| CVE-2026-5545 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a... |
| CVE-2026-4873 | MEDIUM | 5.9 | 0.3% | May 13, 2026 | A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the s... |
| CVE-2026-4798 | HIGH | 7.5 | 0.5% | May 13, 2026 | The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in al... |
| CVE-2026-4782 | MEDIUM | 6.5 | 0.5% | May 13, 2026 | The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2... |
| CVE-2026-44931 | MEDIUM | 5.1 | 0.1% | May 13, 2026 | The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalc... |
