CVE Vulnerability Database
Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45257 | HIGH | 7.3 | 3.9% | May 8, 2026 | A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi... |
| CVE-2024-33724 | MEDIUM | 5.4 | 0.6% | May 8, 2026 | SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php. |
| CVE-2024-33722 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[]. |
| CVE-2024-33288 | HIGH | 7.3 | 0.8% | May 8, 2026 | Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the ... |
| CVE-2024-30167 | MEDIUM | 6.3 | 1.1% | May 8, 2026 | /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm... |
| CVE-2024-27686 | HIGH | 7.5 | 0.6% | May 8, 2026 | Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic... |
| CVE-2023-47268 | MEDIUM | 5.3 | 0.7% | May 8, 2026 | In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar... |
| CVE-2026-8148 | HIGH | 7.8 | 0.1% | May 8, 2026 | NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM... |
| CVE-2026-8138 | HIGH | 8.8 | 0.6% | May 8, 2026 | A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /gof... |
| CVE-2026-8137 | HIGH | 8.8 | 0.5% | May 8, 2026 | A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458... |
| CVE-2026-42279 | MEDIUM | 5.8 | 0.3% | May 8, 2026 | solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entr... |
| CVE-2026-42278 | HIGH | 8.8 | 0.4% | May 8, 2026 | UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of Sm... |
| CVE-2026-42277 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint all... |
| CVE-2026-42276 | MEDIUM | 4.3 | 0.3% | May 8, 2026 | Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_se... |
| CVE-2023-42346 | HIGH | 7.5 | 0.2% | May 8, 2026 | Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host. |
| CVE-2023-42345 | MEDIUM | 6.1 | 0.1% | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. |
| CVE-2023-42344 | HIGH | 7.3 | 2.2% | May 8, 2026 | Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/... |
| CVE-2023-42343 | MEDIUM | 6.1 | 0.6% | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. |
| CVE-2022-45899 | MEDIUM | 6.5 | 0.8% | May 8, 2026 | Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as... |
| CVE-2022-26523 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local ... |
| CVE-2022-26522 | HIGH | 7.8 | 0.2% | May 8, 2026 | The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local ... |
| CVE-2022-23961 | MEDIUM | 6.1 | 0.2% | May 8, 2026 | In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability... |
| CVE-2026-8136 | LOW | 2.4 | 0.2% | May 8, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the fil... |
| CVE-2026-8133 | HIGH | 7.3 | 0.3% | May 8, 2026 | A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknow... |
| CVE-2026-8132 | HIGH | 7.3 | 0.3% | May 8, 2026 | A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /lo... |
