CVE Vulnerability Database
Search and browse 398,366 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39849 | HIGH | 8.8 | 1.0% | May 5, 2026 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1,... |
| CVE-2026-39402 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l... |
| CVE-2026-39383 | HIGH | 7.2 | 0.2% | May 5, 2026 | Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access c... |
| CVE-2026-35579 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati... |
| CVE-2026-35527 | MEDIUM | 5 | 0.3% | May 5, 2026 | Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues ... |
| CVE-2026-7857 | HIGH | 7.3 | 4.2% | May 5, 2026 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file... |
| CVE-2026-7856 | HIGH | 7.3 | 4.6% | May 5, 2026 | A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the comp... |
| CVE-2026-44331 | HIGH | 8.1 | 0.5% | May 5, 2026 | In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap... |
| CVE-2026-40331 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu... |
| CVE-2026-40330 | CRITICAL | 9.3 | 0.4% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu... |
| CVE-2026-40329 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exist... |
| CVE-2026-40280 | HIGH | 7.5 | 0.5% | May 5, 2026 | Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists fo... |
| CVE-2026-38947 | MEDIUM | 6.1 | 0.2% | May 5, 2026 | FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin. |
| CVE-2026-35453 | MEDIUM | 5.4 | 0.2% | May 5, 2026 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1... |
| CVE-2026-35397 | HIGH | 8.8 | 0.6% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili... |
| CVE-2026-34596 | HIGH | 7 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of... |
| CVE-2026-34527 | MEDIUM | 5.3 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniSe... |
| CVE-2026-34464 | HIGH | 8.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe... |
| CVE-2026-34462 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P... |
| CVE-2026-34461 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI... |
| CVE-2026-34459 | HIGH | 8.8 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS... |
| CVE-2026-34458 | HIGH | 8.8 | 0.3% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in... |
| CVE-2026-34084 | CRITICAL | 9.8 | 0.7% | May 5, 2026 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1... |
| CVE-2026-33975 | HIGH | 8.3 | 0.2% | May 5, 2026 | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-... |
| CVE-2026-33489 | HIGH | 7.5 | 0.4% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL s... |
