CVE Vulnerability Database
Search and browse 398,067 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42611 | HIGH | 8.9 | 0.3% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can ... |
| CVE-2026-42610 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.upda... |
| CVE-2026-42609 | HIGH | 8.1 | 0.5% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows ... |
| CVE-2026-42608 | CRITICAL | 9.1 | 0.5% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash c... |
| CVE-2026-42607 | CRITICAL | 9.1 | 3.9% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achie... |
| CVE-2026-3320 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ... |
| CVE-2026-3319 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ... |
| CVE-2026-34092 | HIGH | 7.5 | 0.2% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-34091 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ... |
| CVE-2026-34090 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue ... |
| CVE-2026-34089 | HIGH | 7.5 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2. |
| CVE-2026-34088 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ... |
| CVE-2026-34087 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue a... |
| CVE-2026-34086 | LOW | 2.1 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2... |
| CVE-2026-31247 | HIGH | 7.5 | 0.4% | May 11, 2026 | Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse... |
| CVE-2026-31246 | MEDIUM | 6.5 | 0.7% | May 11, 2026 | GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (... |
| CVE-2025-65418 | HIGH | 7.5 | 0.6% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary... |
| CVE-2025-65417 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page... |
| CVE-2025-65416 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. |
| CVE-2025-65415 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic... |
| CVE-2025-63750 | — | — | — | May 11, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-21709. Reason: This record is a duplicate of CVE-2026-... |
| CVE-2025-61314 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print ... |
| CVE-2025-61313 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr... |
| CVE-2025-61312 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S... |
| CVE-2025-61311 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se... |
