CVE Vulnerability Database
Search and browse 398,130 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4397 | MEDIUM | 6.8 | 0.1% | May 7, 2026 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c... |
| CVE-2025-4386 | MEDIUM | 6.8 | 0.2% | May 7, 2026 | Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ... |
| CVE-2026-44349 | HIGH | 7.1 | 0.3% | May 7, 2026 | Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_finda... |
| CVE-2026-44264 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other... |
| CVE-2026-44263 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe... |
| CVE-2026-42011 | HIGH | 7.4 | — | May 7, 2026 | A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p... |
| CVE-2026-41689 | MEDIUM | 6 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica... |
| CVE-2026-41688 | HIGH | 7.7 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF ... |
| CVE-2026-41687 | MEDIUM | 4.3 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in en... |
| CVE-2026-41654 | HIGH | 8.1 | 0.4% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de... |
| CVE-2026-41650 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version ... |
| CVE-2026-41519 | MEDIUM | 5.4 | 0.2% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions ... |
| CVE-2026-41505 | HIGH | 8.7 | 0.3% | May 7, 2026 | RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation ... |
| CVE-2026-41422 | HIGH | 8.3 | 0.3% | May 7, 2026 | Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column an... |
| CVE-2026-36458 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated i... |
| CVE-2026-32686 | MEDIUM | 6.9 | 0.3% | May 7, 2026 | Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The ... |
| CVE-2025-67202 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul... |
| CVE-2025-63706 | CRITICAL | 9.8 | 1.5% | May 7, 2026 | NPM package next-npm-version1.0.1 is vulnerable to Command injection. |
| CVE-2025-63705 | HIGH | 8.8 | 1.2% | May 7, 2026 | NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. |
| CVE-2026-6795 | CRITICAL | 9.6 | 0.2% | May 7, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive... |
| CVE-2026-41685 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by auth... |
| CVE-2026-41684 | MEDIUM | 6.5 | 0.4% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back... |
| CVE-2026-41648 | MEDIUM | 5 | 0.3% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs... |
| CVE-2026-41647 | MEDIUM | 6.5 | 0.4% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an ... |
| CVE-2026-41589 | CRITICAL | 9.6 | 0.4% | May 7, 2026 | Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP... |
