CVE Vulnerability Database
Search and browse 398,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28830 | MEDIUM | 4.7 | 0.1% | May 11, 2026 | A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able t... |
| CVE-2026-28819 | MEDIUM | 5.4 | 7.1% | May 11, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1... |
| CVE-2026-20696 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ... |
| CVE-2026-8321 | HIGH | 7.3 | 0.4% | May 11, 2026 | A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the f... |
| CVE-2026-8320 | MEDIUM | 4.7 | 0.2% | May 11, 2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode... |
| CVE-2026-8319 | MEDIUM | 5.5 | 0.4% | May 11, 2026 | A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this iss... |
| CVE-2026-6146 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores c... |
| CVE-2026-45026 | MEDIUM | 6.8 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln... |
| CVE-2026-45025 | MEDIUM | 6.8 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln... |
| CVE-2026-42887 | MEDIUM | 4.5 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne... |
| CVE-2026-42886 | MEDIUM | 4.9 | 0.3% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec... |
| CVE-2026-42885 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpo... |
| CVE-2026-42884 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col... |
| CVE-2026-42883 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo... |
| CVE-2026-42882 | CRITICAL | 9.4 | 0.6% | May 11, 2026 | oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused ... |
| CVE-2026-42876 | MEDIUM | 4.9 | 0.2% | May 11, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-42875 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-42874 | LOW | 3.7 | 0.2% | May 11, 2026 | Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ... |
| CVE-2026-42873 | NONE | 0 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with m... |
| CVE-2026-42872 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) v... |
| CVE-2026-42870 | MEDIUM | 6.4 | 0.3% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw... |
| CVE-2026-42869 | CRITICAL | 10 | 0.4% | May 11, 2026 | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,... |
| CVE-2026-42565 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | @workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec... |
| CVE-2026-42050 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9... |
| CVE-2026-36734 | HIGH | 8.8 | 1.0% | May 11, 2026 | EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su... |
