CVE Vulnerability Database
Search and browse 398,067 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38566 | HIGH | 8.1 | 0.2% | May 11, 2026 | HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change a... |
| CVE-2026-36983 | HIGH | 7.3 | 1.2% | May 11, 2026 | D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The man... |
| CVE-2026-36962 | HIGH | 7.3 | 0.4% | May 11, 2026 | SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve... |
| CVE-2026-34095 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/... |
| CVE-2026-34094 | LOW | 3.8 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Art... |
| CVE-2026-34093 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-30635 | HIGH | 8.1 | 1.0% | May 11, 2026 | Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via ... |
| CVE-2026-2393 | HIGH | 7.1 | 0.3% | May 11, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` fun... |
| CVE-2026-2291 | HIGH | 7.3 | 0.8% | May 11, 2026 | dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS... |
| CVE-2026-44738 | HIGH | 7.7 | 0.3% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.page... |
| CVE-2026-44737 | MEDIUM | 6.2 | 0.3% | May 11, 2026 | grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra... |
| CVE-2026-42845 | HIGH | 7.7 | 0.6% | May 11, 2026 | The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-con... |
| CVE-2026-42843 | HIGH | 8.8 | 0.4% | May 11, 2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configur... |
| CVE-2026-42842 | MEDIUM | 5.4 | 0.1% | May 11, 2026 | The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) v... |
| CVE-2026-42603 | HIGH | 8.8 | 0.3% | May 11, 2026 | OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m... |
| CVE-2026-42349 | HIGH | 8.1 | 0.2% | May 11, 2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related auth... |
| CVE-2026-36906 | MEDIUM | 6.1 | 0.3% | May 11, 2026 | Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log ... |
| CVE-2026-33362 | HIGH | 8.6 | 0.2% | May 11, 2026 | In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps ... |
| CVE-2026-33361 | HIGH | 7.5 | 0.2% | May 11, 2026 | In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), a... |
| CVE-2026-33359 | HIGH | 7.5 | 0.3% | May 11, 2026 | In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion s... |
| CVE-2026-33357 | HIGH | 7.5 | 0.2% | May 11, 2026 | In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and... |
| CVE-2026-33356 | HIGH | 7.7 | 0.3% | May 11, 2026 | In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to gl... |
| CVE-2026-31254 | HIGH | 7.3 | 0.2% | May 11, 2026 | The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection ... |
| CVE-2026-31253 | HIGH | 7.3 | 0.2% | May 11, 2026 | The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an ins... |
| CVE-2026-31252 | MEDIUM | 5.7 | 0.1% | May 11, 2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera... |
