CVE Vulnerability Database
Search and browse 398,007 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15463 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers... |
| CVE-2026-8449 | — | — | — | May 12, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn. |
| CVE-2026-45227 | HIGH | 8.8 | 0.2% | May 12, 2026 | Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated ... |
| CVE-2026-45226 | HIGH | 7.6 | 0.3% | May 12, 2026 | Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users ... |
| CVE-2026-45225 | HIGH | 7.6 | 0.4% | May 12, 2026 | Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users t... |
| CVE-2026-44871 | HIGH | 8.8 | 1.2% | May 12, 2026 | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS... |
| CVE-2026-44307 | HIGH | 8.7 | 0.6% | May 12, 2026 | Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\... |
| CVE-2026-44306 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f... |
| CVE-2026-44305 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP aut... |
| CVE-2026-44304 | HIGH | 8.1 | 0.2% | May 12, 2026 | Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) construc... |
| CVE-2026-44302 | HIGH | 7.5 | 0.3% | May 12, 2026 | Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStr... |
| CVE-2026-44301 | HIGH | 8.1 | 0.3% | May 12, 2026 | Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipel... |
| CVE-2026-44296 | HIGH | 7.5 | 0.3% | May 12, 2026 | Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vul... |
| CVE-2026-44262 | CRITICAL | 9.4 | 5.9% | May 12, 2026 | Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints ar... |
| CVE-2026-44260 | HIGH | 8.1 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is int... |
| CVE-2026-44259 | MEDIUM | 4.6 | 0.1% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME t... |
| CVE-2026-44258 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targe... |
| CVE-2026-44257 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk usin... |
| CVE-2026-44242 | LOW | 3.7 | 0.2% | May 12, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
| CVE-2026-44241 | HIGH | 7.5 | 0.4% | May 12, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
| CVE-2026-44015 | CRITICAL | 9.9 | 0.3% | May 12, 2026 | Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Serve... |
| CVE-2026-43948 | CRITICAL | 9.9 | 0.4% | May 12, 2026 | wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_... |
| CVE-2026-42855 | HIGH | 7.5 | 0.4% | May 12, 2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr... |
| CVE-2026-42854 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr... |
| CVE-2026-42844 | HIGH | 8.8 | 0.3% | May 12, 2026 | Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write ca... |
