CVE Vulnerability Database
Search and browse 398,067 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42870 | MEDIUM | 6.4 | 0.3% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw... |
| CVE-2026-42869 | CRITICAL | 10 | 0.4% | May 11, 2026 | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,... |
| CVE-2026-42565 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | @workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec... |
| CVE-2026-42050 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9... |
| CVE-2026-36734 | HIGH | 8.8 | 1.0% | May 11, 2026 | EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su... |
| CVE-2026-2614 | HIGH | 7.5 | 2.9% | May 11, 2026 | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 ... |
| CVE-2022-4988 | HIGH | 7.3 | 0.3% | May 11, 2026 | Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains versi... |
| CVE-2026-8318 | MEDIUM | 5.5 | 0.4% | May 11, 2026 | A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by t... |
| CVE-2026-7790 | HIGH | 7.5 | 0.4% | May 11, 2026 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. T... |
| CVE-2026-45224 | HIGH | 7.1 | 0.1% | May 11, 2026 | Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allow... |
| CVE-2026-45223 | HIGH | 8.8 | 0.4% | May 11, 2026 | Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path whe... |
| CVE-2026-45222 | MEDIUM | 6.9 | 0.1% | May 11, 2026 | Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with def... |
| CVE-2026-43969 | LOW | 3.2 | 0.1% | May 11, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split... |
| CVE-2026-43968 | MEDIUM | 4 | 0.2% | May 11, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin... |
| CVE-2026-42871 | MEDIUM | 6.9 | 0.3% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa... |
| CVE-2026-42866 | MEDIUM | 6.7 | 0.1% | May 11, 2026 | Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write... |
| CVE-2026-42864 | CRITICAL | 9.9 | 0.3% | May 11, 2026 | FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint ... |
| CVE-2026-8305 | CRITICAL | 9.8 | 0.6% | May 11, 2026 | A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookR... |
| CVE-2026-7308 | MEDIUM | 5.4 | 0.3% | May 11, 2026 | An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript t... |
| CVE-2026-7210 | HIGH | 7.5 | 0.8% | May 11, 2026 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow... |
| CVE-2026-5266 | LOW | 2.3 | 0.2% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerabil... |
| CVE-2026-5172 | HIGH | 7.3 | 2.7% | May 11, 2026 | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and ... |
| CVE-2026-4893 | MEDIUM | 5.3 | 2.7% | May 11, 2026 | An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS pac... |
| CVE-2026-4892 | HIGH | 8.4 | 0.8% | May 11, 2026 | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute... |
| CVE-2026-4891 | MEDIUM | 5.3 | 6.4% | May 11, 2026 | A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a den... |
