CVE Vulnerability Database
Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8142 | MEDIUM | 6.5 | 0.1% | May 7, 2026 | VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use... |
| CVE-2026-8088 | MEDIUM | 5.5 | 0.2% | May 7, 2026 | A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the ... |
| CVE-2026-8087 | HIGH | 7.8 | 0.2% | May 7, 2026 | A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frm... |
| CVE-2026-43510 | MEDIUM | 5.9 | 0.4% | May 7, 2026 | manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assi... |
| CVE-2026-42501 | HIGH | 7.5 | 0.2% | May 7, 2026 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa... |
| CVE-2026-42499 | HIGH | 7.5 | 0.8% | May 7, 2026 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. |
| CVE-2026-42259 | MEDIUM | 5.1 | 0.3% | May 7, 2026 | Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-... |
| CVE-2026-42241 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.... |
| CVE-2026-42239 | HIGH | 8.1 | 0.3% | May 7, 2026 | Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess... |
| CVE-2026-42225 | MEDIUM | 5.9 | 0.2% | May 7, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, ... |
| CVE-2026-39836 | HIGH | 7.5 | 0.6% | May 7, 2026 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). |
| CVE-2026-39826 | MEDIUM | 6.1 | 0.4% | May 7, 2026 | If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit... |
| CVE-2026-39825 | MEDIUM | 5.3 | 0.4% | May 7, 2026 | ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi... |
| CVE-2026-39823 | MEDIUM | 6.1 | 0.3% | May 7, 2026 | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu... |
| CVE-2026-39820 | HIGH | 7.5 | 0.8% | May 7, 2026 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion... |
| CVE-2026-39819 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp").... |
| CVE-2026-39817 | MEDIUM | 5.9 | 0.2% | May 7, 2026 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa... |
| CVE-2026-33814 | HIGH | 7.5 | 0.8% | May 7, 2026 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei... |
| CVE-2026-33811 | HIGH | 7.5 | 0.8% | May 7, 2026 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a... |
| CVE-2026-8086 | HIGH | 7.8 | 0.2% | May 7, 2026 | A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file f... |
| CVE-2026-8084 | MEDIUM | 5.5 | 0.3% | May 7, 2026 | A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the f... |
| CVE-2026-8083 | HIGH | 7.3 | 0.3% | May 7, 2026 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the... |
| CVE-2026-44742 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as e... |
| CVE-2026-44244 | HIGH | 7.8 | 0.2% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value... |
| CVE-2026-44243 | HIGH | 7.1 | 0.4% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPyt... |
