CVE Vulnerability Database
Search and browse 398,382 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7855 | HIGH | 7.2 | 1.1% | May 5, 2026 | A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /... |
| CVE-2026-7854 | CRITICAL | 9.8 | 5.9% | May 5, 2026 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function ... |
| CVE-2026-42997 | HIGH | 7.7 | 0.4% | May 5, 2026 | An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut... |
| CVE-2026-38428 | CRITICAL | 9.8 | 0.4% | May 5, 2026 | Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a G... |
| CVE-2026-31835 | MEDIUM | 5.4 | 0.2% | May 5, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authenticatio... |
| CVE-2026-30923 | HIGH | 7.5 | 0.4% | May 5, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsec... |
| CVE-2026-27960 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 t... |
| CVE-2026-7853 | CRITICAL | 9.8 | 1.5% | May 5, 2026 | A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.a... |
| CVE-2026-7851 | HIGH | 7.3 | 4.1% | May 5, 2026 | A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The... |
| CVE-2026-7847 | LOW | 2.6 | 0.2% | May 5, 2026 | A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_... |
| CVE-2026-43002 | MEDIUM | 5.3 | 0.4% | May 5, 2026 | An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session stor... |
| CVE-2026-38432 | MEDIUM | 6.1 | 0.2% | May 5, 2026 | ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with ... |
| CVE-2026-38431 | CRITICAL | 9.8 | 0.4% | May 5, 2026 | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to crea... |
| CVE-2026-38429 | CRITICAL | 9.8 | 0.3% | May 5, 2026 | OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML par... |
| CVE-2026-25589 | HIGH | 8.8 | 1.4% | May 5, 2026 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module ... |
| CVE-2026-25588 | HIGH | 8.8 | 1.0% | May 5, 2026 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does no... |
| CVE-2026-25243 | HIGH | 8.8 | 3.0% | May 5, 2026 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper... |
| CVE-2026-23631 | HIGH | 8.1 | 1.8% | May 5, 2026 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke... |
| CVE-2026-23479 | HIGH | 8.8 | 1.3% | May 5, 2026 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han... |
| CVE-2026-7865 | HIGH | 7.4 | 0.8% | May 5, 2026 | A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argume... |
| CVE-2026-7846 | LOW | 2.6 | 0.2% | May 5, 2026 | A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the... |
| CVE-2026-7845 | LOW | 2.6 | 0.1% | May 5, 2026 | A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.toby... |
| CVE-2026-7844 | MEDIUM | 6.3 | 0.3% | May 5, 2026 | A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function... |
| CVE-2026-7412 | HIGH | 8.6 | 0.5% | May 5, 2026 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validat... |
| CVE-2026-7411 | CRITICAL | 10 | 3.7% | May 5, 2026 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTT... |
