CVE Vulnerability Database
Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42284 | CRITICAL | 9.8 | 0.6% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_... |
| CVE-2026-42215 | HIGH | 8.8 | 0.7% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP... |
| CVE-2026-42214 | HIGH | 7.8 | 0.2% | May 7, 2026 | Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFrom... |
| CVE-2026-41906 | HIGH | 7.1 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change ... |
| CVE-2026-41905 | HIGH | 7.7 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san... |
| CVE-2026-41904 | HIGH | 7.6 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with... |
| CVE-2026-41903 | MEDIUM | 5.4 | 0.3% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold... |
| CVE-2026-41902 | CRITICAL | 9.1 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s... |
| CVE-2026-41653 | HIGH | 7 | 0.4% | May 7, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerabilit... |
| CVE-2026-8081 | MEDIUM | 6.3 | 0.2% | May 7, 2026 | A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality... |
| CVE-2026-37709 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958... |
| CVE-2026-7415 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read ... |
| CVE-2026-7414 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials ar... |
| CVE-2026-7413 | CRITICAL | 9.8 | 0.6% | May 7, 2026 | A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen... |
| CVE-2026-7821 | CRITICAL | 9.1 | 0.5% | May 7, 2026 | Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen... |
| CVE-2026-6973 | HIGH | 7.2 | 34.5% | May 7, 2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic... |
| CVE-2026-5788 | CRITICAL | 9.8 | 0.8% | May 7, 2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat... |
| CVE-2026-5787 | CRITICAL | 9.1 | 0.7% | May 7, 2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut... |
| CVE-2026-5786 | HIGH | 8.8 | 0.7% | May 7, 2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote... |
| CVE-2026-36388 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/... |
| CVE-2026-36387 | MEDIUM | 6.5 | 0.3% | May 7, 2026 | A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This... |
| CVE-2026-36341 | MEDIUM | 5.4 | 0.2% | May 7, 2026 | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp... |
| CVE-2025-65122 | HIGH | 7.5 | 0.3% | May 7, 2026 | Regex Denial of Service in youtube-regex npm package through version 1.0.5. |
| CVE-2025-63704 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ... |
| CVE-2025-63703 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). |
