CVE Vulnerability Database
Search and browse 398,020 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31216 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m... |
| CVE-2026-31215 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch ... |
| CVE-2026-31214 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (... |
| CVE-2026-30810 | HIGH | 8.8 | 0.3% | May 12, 2026 | Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pand... |
| CVE-2026-30808 | HIGH | 8.1 | 0.3% | May 12, 2026 | Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777... |
| CVE-2026-30807 | HIGH | 8.8 | 0.1% | May 12, 2026 | Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This i... |
| CVE-2026-30805 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affect... |
| CVE-2023-30059 | MEDIUM | 5.4 | 0.2% | May 12, 2026 | An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other use... |
| CVE-2023-27753 | HIGH | 8 | 0.3% | May 12, 2026 | An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c... |
| CVE-2026-8401 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir... |
| CVE-2026-8368 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect... |
| CVE-2026-8111 | HIGH | 8.8 | 0.9% | May 12, 2026 | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack... |
| CVE-2026-8110 | HIGH | 7.8 | 0.2% | May 12, 2026 | Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti... |
| CVE-2026-8109 | MEDIUM | 6.5 | 0.7% | May 12, 2026 | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen... |
| CVE-2026-8051 | HIGH | 7.2 | 1.9% | May 12, 2026 | OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with... |
| CVE-2026-8043 | CRITICAL | 9.6 | 0.9% | May 12, 2026 | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read... |
| CVE-2026-7432 | HIGH | 7 | 0.3% | May 12, 2026 | A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges... |
| CVE-2026-7431 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local a... |
| CVE-2026-6866 | HIGH | 7.5 | 0.3% | May 12, 2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclo... |
| CVE-2026-5061 | MEDIUM | 4.7 | 0.1% | May 12, 2026 | The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper tha... |
| CVE-2026-43983 | HIGH | 8.1 | 0.2% | May 12, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th... |
| CVE-2026-43939 | HIGH | 7.3 | 0.2% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc... |
| CVE-2026-43938 | HIGH | 8.1 | 0.3% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE... |
| CVE-2026-43937 | HIGH | 8.8 | 0.5% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects... |
| CVE-2026-42260 | HIGH | 8.2 | 0.2% | May 12, 2026 | Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to ... |
