CVE Vulnerability Database
Search and browse 398,143 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40004 | HIGH | 7.8 | 0.1% | May 7, 2026 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execut... |
| CVE-2026-4807 | MEDIUM | 6.5 | 0.5% | May 7, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu... |
| CVE-2026-44600 | MEDIUM | 5.3 | 0.4% | May 7, 2026 | Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-202... |
| CVE-2026-44599 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008. |
| CVE-2026-6222 | MEDIUM | 5.3 | 0.4% | May 7, 2026 | The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1.... |
| CVE-2026-40003 | MEDIUM | 6.8 | 0.3% | May 7, 2026 | ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l... |
| CVE-2026-44597 | CRITICAL | 9.1 | 0.4% | May 7, 2026 | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,... |
| CVE-2026-6278 | — | — | — | May 6, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-41484 | MEDIUM | 5.9 | 0.3% | May 6, 2026 | OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In ver... |
| CVE-2026-41483 | MEDIUM | 5.9 | 0.3% | May 6, 2026 | OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie... |
| CVE-2026-41417 | MEDIUM | 5.3 | 0.3% | May 6, 2026 | Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created f... |
| CVE-2026-41310 | MEDIUM | 5.3 | 0.3% | May 6, 2026 | OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin ... |
| CVE-2026-40296 | MEDIUM | 5.4 | 0.2% | May 6, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars e... |
| CVE-2026-3291 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated vers... |
| CVE-2026-40332 | MEDIUM | 5.3 | 0.3% | May 6, 2026 | Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application... |
| CVE-2026-40281 | CRITICAL | 9.1 | 0.6% | May 6, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v... |
| CVE-2026-40251 | MEDIUM | 6.5 | 0.4% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora... |
| CVE-2026-40243 | MEDIUM | 4.8 | 0.2% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OV... |
| CVE-2026-40197 | MEDIUM | 6.5 | 0.3% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora... |
| CVE-2026-40195 | MEDIUM | 6.5 | 0.4% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora... |
| CVE-2026-8033 | MEDIUM | 5.5 | 0.3% | May 6, 2026 | A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of t... |
| CVE-2026-8032 | HIGH | 7.3 | 0.3% | May 6, 2026 | A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of... |
| CVE-2026-44118 | HIGH | 8.5 | 0.1% | May 6, 2026 | OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request heade... |
| CVE-2026-44117 | MEDIUM | 6.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips U... |
| CVE-2026-44116 | HIGH | 8.6 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t... |
