CVE Vulnerability Database
Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7475 | MEDIUM | 6.4 | 0.2% | May 8, 2026 | The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom pos... |
| CVE-2026-6213 | CRITICAL | 10 | 0.3% | May 8, 2026 | A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an... |
| CVE-2026-5341 | MEDIUM | 6.4 | 0.3% | May 8, 2026 | The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr... |
| CVE-2026-7330 | HIGH | 7.2 | 0.4% | May 8, 2026 | The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ... |
| CVE-2026-5127 | HIGH | 8.8 | 1.0% | May 8, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-44928 | MEDIUM | 5.3 | 0.2% | May 8, 2026 | In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. |
| CVE-2026-44927 | MEDIUM | 5.3 | 0.2% | May 8, 2026 | In uriparser before 1.0.2, there is pointer difference truncation to int in various places. |
| CVE-2026-43284 | HIGH | 8.8 | 93.2% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb fra... |
| CVE-2013-10075 | CRITICAL | 9.1 | 0.4% | May 8, 2026 | Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::... |
| CVE-2026-8149 | MEDIUM | 5.1 | 0.2% | May 8, 2026 | A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the ... |
| CVE-2026-8069 | HIGH | 7.8 | 0.1% | May 8, 2026 | PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes ... |
| CVE-2026-4935 | HIGH | 8.6 | 0.3% | May 8, 2026 | The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before ... |
| CVE-2026-44916 | LOW | 3 | 0.3% | May 8, 2026 | In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered wit... |
| CVE-2025-69691 | CRITICAL | 9.9 | 0.5% | May 8, 2026 | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ... |
| CVE-2025-69690 | CRITICAL | 9.1 | 0.6% | May 8, 2026 | Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob... |
| CVE-2025-69599 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e... |
| CVE-2025-67888 | HIGH | 7.3 | 1.2% | May 8, 2026 | An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /... |
| CVE-2025-67887 | CRITICAL | 9.8 | 1.5% | May 8, 2026 | 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla... |
| CVE-2025-67886 | MEDIUM | 6.3 | 1.0% | May 8, 2026 | Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat... |
| CVE-2025-55449 | HIGH | 7.3 | 0.3% | May 8, 2026 | AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us... |
| CVE-2023-46453 | CRITICAL | 9.8 | 0.8% | May 8, 2026 | Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device... |
| CVE-2024-53326 | HIGH | 7.3 | 0.5% | May 8, 2026 | LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(... |
| CVE-2024-51092 | CRITICAL | 9.1 | 6.9% | May 8, 2026 | LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr... |
| CVE-2024-46508 | HIGH | 7.5 | 0.4% | May 8, 2026 | yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting ... |
| CVE-2024-46507 | HIGH | 7.3 | 3.9% | May 8, 2026 | A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor... |
