CVE Vulnerability Database
Search and browse 398,082 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42205 | HIGH | 8.8 | 0.3% | May 8, 2026 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne... |
| CVE-2026-42202 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-... |
| CVE-2026-42199 | MEDIUM | 6.2 | 0.1% | May 8, 2026 | Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand... |
| CVE-2026-42195 | LOW | 3.4 | 0.2% | May 8, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts... |
| CVE-2026-42193 | CRITICAL | 9.1 | 0.1% | May 8, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accep... |
| CVE-2026-42192 | MEDIUM | 5.4 | 0.2% | May 8, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X... |
| CVE-2026-41517 | NONE | 0 | 0.3% | May 8, 2026 | Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows at... |
| CVE-2026-41486 | HIGH | 8.8 | 0.5% | May 8, 2026 | Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ... |
| CVE-2026-44400 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile ... |
| CVE-2026-7807 | HIGH | 8.8 | 0.3% | May 8, 2026 | SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary... |
| CVE-2026-44694 | CRITICAL | 9.1 | 0.2% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From ... |
| CVE-2026-42282 | MEDIUM | 4.3 | 0.3% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-42190 | MEDIUM | 5.3 | 0.1% | May 8, 2026 | RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd... |
| CVE-2026-42189 | HIGH | 7.5 | 0.5% | May 8, 2026 | Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili... |
| CVE-2026-42185 | MEDIUM | 5.5 | 0.3% | May 8, 2026 | People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,... |
| CVE-2026-42181 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli... |
| CVE-2026-42180 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-priv... |
| CVE-2026-42176 | MEDIUM | 6.7 | 0.2% | May 8, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat... |
| CVE-2026-42160 | CRITICAL | 10 | 0.2% | May 8, 2026 | Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F... |
| CVE-2026-41495 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-8178 | CRITICAL | 9.2 | 0.6% | May 8, 2026 | An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load ... |
| CVE-2026-41511 | MEDIUM | 5.5 | 0.2% | May 8, 2026 | OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto... |
| CVE-2026-29203 | HIGH | 8.8 | 0.5% | May 8, 2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on ... |
| CVE-2026-29202 | HIGH | 8.8 | 0.8% | May 8, 2026 | Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution... |
| CVE-2026-29201 | HIGH | 8.6 | 0.4% | May 8, 2026 | Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f... |
