CVE Database

52246+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-34926
6.7 MEDIUM KEV

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to …

May 21, 2026
CVE-2026-45254
6.5 MEDIUM

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was …

May 21, 2026
CVE-2026-45252
5.5 MEDIUM

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended …

May 21, 2026
CVE-2026-42396
4.9 MEDIUM

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

May 21, 2026
CVE-2026-42002
5.9 MEDIUM

Concurrency and locking defects in GSS-TSIG

May 21, 2026
CVE-2026-42000
6.8 MEDIUM

Insufficient Validation of Names During AXFR

May 21, 2026
CVE-2026-41999
4.8 MEDIUM

Incorrect Behaviour of Views with TCP PROXY Requests

May 21, 2026
CVE-2026-5434
5.9 MEDIUM

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially …

May 21, 2026
CVE-2026-27393
5.3 MEDIUM

Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through …

May 21, 2026
CVE-2026-27349
4.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data. This issue affects Mail …

May 21, 2026
CVE-2026-22880
6.1 MEDIUM

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling …

May 21, 2026
CVE-2026-4055
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team …

May 21, 2026
CVE-2026-44076
6.7 MEDIUM

Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a …

May 21, 2026
CVE-2026-44073
5.0 MEDIUM

Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated …

May 21, 2026
CVE-2026-44067
4.2 MEDIUM

A heap over-read in extended attribute (EA) header parsing in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to obtain limited information or cause …

May 21, 2026
CVE-2026-44065
4.2 MEDIUM

An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent network attacker to modify limited data or cause a minor …

May 21, 2026
CVE-2026-44063
4.2 MEDIUM

An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP …

May 21, 2026
CVE-2026-44061
5.9 MEDIUM

Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker to recover authentication credentials via timing analysis.

May 21, 2026
CVE-2026-44059
4.5 MEDIUM

A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited information, modify limited data, or …

May 21, 2026
CVE-2026-44056
6.4 MEDIUM

A stack-based buffer overflow in desktop.c in Netatalk 1.3 through 4.2.2 allows a remote authenticated attacker to cause a denial of service, obtain limited information, …

May 21, 2026
CVE-2026-44054
6.5 MEDIUM

Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, which allows a remote authenticated attacker to cause a denial of service …

May 21, 2026
CVE-2026-2734
6.5 MEDIUM

In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is …

May 21, 2026
CVE-2026-1543
6.4 MEDIUM

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 3.15.2 due …

May 21, 2026
CVE-2026-4811
4.9 MEDIUM

The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

May 21, 2026
CVE-2026-1881
4.3 MEDIUM

The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.52.2 via the get_sponsored_meta AJAX action …

May 21, 2026
CVE-2026-9149
6.5 MEDIUM

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values …

May 21, 2026
CVE-2026-9150
6.5 MEDIUM

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An …

May 20, 2026
CVE-2026-40102
6.5 MEDIUM

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression …

May 20, 2026
CVE-2026-40094
4.3 MEDIUM

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and stores …

May 20, 2026
CVE-2026-39960
5.4 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a textarea custom …

May 20, 2026
CVE-2026-9124
5.3 MEDIUM

Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to …

May 20, 2026
CVE-2026-9122
6.5 MEDIUM

Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process …

May 20, 2026
CVE-2026-9116
4.3 MEDIUM

Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

May 20, 2026
CVE-2026-9115
4.3 MEDIUM

Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted …

May 20, 2026
CVE-2026-9113
4.3 MEDIUM

Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory …

May 20, 2026
CVE-2026-9110
4.2 MEDIUM

Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI …

May 20, 2026
CVE-2026-47099
6.1 MEDIUM

TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted …

May 20, 2026
CVE-2026-39311
6.8 MEDIUM

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw …

May 20, 2026
CVE-2026-35016
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35015
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35014
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35013
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values …

May 20, 2026
CVE-2026-35012
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35011
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35010
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35009
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35008
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-35007
4.6 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 20, 2026
CVE-2026-2813
4.7 MEDIUM

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, …

May 20, 2026
CVE-2026-2812
5.3 MEDIUM

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to …

May 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.