CVE Vulnerability Database
Search and browse 398,007 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8053 | HIGH | 8.8 | 0.6% | May 13, 2026 | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv... |
| CVE-2026-6888 | HIGH | 7.2 | 0.4% | May 13, 2026 | Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitr... |
| CVE-2025-62627 | HIGH | 7.2 | 0.1% | May 13, 2026 | An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ... |
| CVE-2025-62624 | HIGH | 8.8 | 0.1% | May 13, 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca... |
| CVE-2025-62623 | HIGH | 8.8 | 0.1% | May 13, 2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca... |
| CVE-2025-61972 | HIGH | 8.5 | 0.1% | May 13, 2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma... |
| CVE-2025-61971 | MEDIUM | 5.9 | 0.1% | May 13, 2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf... |
| CVE-2024-36315 | MEDIUM | 5.7 | 0.1% | May 13, 2026 | Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten... |
| CVE-2026-8108 | HIGH | 7.8 | 0.1% | May 12, 2026 | The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions. |
| CVE-2026-5371 | HIGH | 7.1 | 0.3% | May 12, 2026 | The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnera... |
| CVE-2026-44548 | HIGH | 8.1 | 0.1% | May 12, 2026 | ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attack... |
| CVE-2026-44547 | CRITICAL | 9.6 | 0.2% | May 12, 2026 | ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The ... |
| CVE-2026-44352 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-44347 | MEDIUM | 6.5 | 0.1% | May 12, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate ... |
| CVE-2026-44341 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthentica... |
| CVE-2026-44245 | MEDIUM | 6.1 | 0.2% | May 12, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directiv... |
| CVE-2026-43685 | HIGH | 7.2 | 0.5% | May 12, 2026 | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject a... |
| CVE-2026-43680 | HIGH | 7.2 | 0.5% | May 12, 2026 | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a... |
| CVE-2026-42289 | HIGH | 8.8 | 0.1% | May 12, 2026 | ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and... |
| CVE-2026-42288 | CRITICAL | 10 | 0.6% | May 12, 2026 | ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-... |
| CVE-2026-42158 | LOW | 2.3 | 0.2% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-42157 | MEDIUM | 5.1 | 0.3% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-42156 | HIGH | 7.1 | 0.3% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-41901 | CRITICAL | 9 | 0.4% | May 12, 2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security ... |
| CVE-2026-1250 | HIGH | 7.5 | 0.3% | May 12, 2026 | The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection vi... |
