CVE Vulnerability Database
Search and browse 398,143 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41674 | HIGH | 7.5 | 0.5% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41673 | HIGH | 7.5 | 0.6% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41672 | HIGH | 7.5 | 0.4% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41671 | MEDIUM | 6.8 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modu... |
| CVE-2026-41670 | HIGH | 8.2 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO... |
| CVE-2026-41669 | HIGH | 8.2 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement... |
| CVE-2026-41663 | LOW | 3.5 | 0.1% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio... |
| CVE-2026-41662 | MEDIUM | 5.2 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth... |
| CVE-2026-41661 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbi... |
| CVE-2026-41660 | HIGH | 7.1 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authen... |
| CVE-2026-41659 | LOW | 2.7 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (m... |
| CVE-2026-41658 | MEDIUM | 6.5 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author... |
| CVE-2026-41657 | MEDIUM | 4.9 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker... |
| CVE-2026-41656 | MEDIUM | 4.5 | 0.4% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php ... |
| CVE-2026-41655 | MEDIUM | 6.5 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali... |
| CVE-2026-41640 | HIGH | 8.8 | 1.9% | May 7, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-41587 | HIGH | 8.6 | 0.5% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41203 | CRITICAL | 9.4 | 0.5% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41202 | CRITICAL | 9.4 | 0.5% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41201 | CRITICAL | 9.1 | 0.3% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41142 | HIGH | 8.8 | 0.4% | May 7, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-41004 | MEDIUM | 4.4 | 0.2% | May 7, 2026 | When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp... |
| CVE-2026-41002 | HIGH | 8.1 | 0.2% | May 7, 2026 | The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi... |
| CVE-2026-40982 | CRITICAL | 9.1 | 0.7% | May 7, 2026 | Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server ... |
| CVE-2026-40981 | HIGH | 7.5 | 0.4% | May 7, 2026 | When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co... |
