CVE Database

52246+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-34664
6.3 MEDIUM

Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could …

May 12, 2026
CVE-2026-23822
5.3 MEDIUM

A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could …

May 12, 2026
CVE-2026-5146
4.3 MEDIUM

Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing …

May 12, 2026
CVE-2026-44279
5.5 MEDIUM

A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker …

May 12, 2026
CVE-2026-44204
6.5 MEDIUM

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets …

May 12, 2026
CVE-2026-42891
6.5 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

May 12, 2026
CVE-2026-42838
5.4 MEDIUM

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over …

May 12, 2026
CVE-2026-42830
6.5 MEDIUM

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-42541
4.3 MEDIUM

Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft …

May 12, 2026
CVE-2026-42348
5.9 MEDIUM

OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses from the OpAMP server over HTTP, the OpAMP client allocates an …

May 12, 2026
CVE-2026-42177
5.3 MEDIUM

linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is …

May 12, 2026
CVE-2026-42175
6.5 MEDIUM

requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in …

May 12, 2026
CVE-2026-42045
6.2 MEDIUM

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags …

May 12, 2026
CVE-2026-41614
6.2 MEDIUM

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

May 12, 2026
CVE-2026-41612
5.5 MEDIUM

Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

May 12, 2026
CVE-2026-41610
6.3 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

May 12, 2026
CVE-2026-41100
4.4 MEDIUM

Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

May 12, 2026
CVE-2026-41097
6.7 MEDIUM

Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

May 12, 2026
CVE-2026-40421
4.3 MEDIUM

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

May 12, 2026
CVE-2026-40416
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

May 12, 2026
CVE-2026-40380
6.2 MEDIUM

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

May 12, 2026
CVE-2026-40374
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.

May 12, 2026
CVE-2026-35440
5.5 MEDIUM

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

May 12, 2026
CVE-2026-35429
4.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

May 12, 2026
CVE-2026-35423
5.4 MEDIUM

Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.

May 12, 2026
CVE-2026-35422
6.5 MEDIUM

Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.

May 12, 2026
CVE-2026-35419
5.5 MEDIUM

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

May 12, 2026
CVE-2026-34663
5.5 MEDIUM

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

May 12, 2026
CVE-2026-34662
5.5 MEDIUM

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit …

May 12, 2026
CVE-2026-34350
6.5 MEDIUM

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.

May 12, 2026
CVE-2026-34339
5.5 MEDIUM

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.

May 12, 2026
CVE-2026-32209
4.4 MEDIUM

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.

May 12, 2026
CVE-2026-32185
5.5 MEDIUM

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

May 12, 2026
CVE-2026-32175
4.3 MEDIUM

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories …

May 12, 2026
CVE-2026-32170
6.7 MEDIUM

Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-31245
5.3 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memories). The endpoint allows unauthenticated users to submit arbitrary …

May 12, 2026
CVE-2026-31244
6.5 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrary …

May 12, 2026
CVE-2026-31243
6.5 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated …

May 12, 2026
CVE-2026-31241
6.5 MEDIUM

The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories). The endpoint allows unauthenticated users to delete memory …

May 12, 2026
CVE-2026-25690
4.3 MEDIUM

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through …

May 12, 2026
CVE-2026-25088
5.4 MEDIUM

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR …

May 12, 2026
CVE-2026-21530
6.7 MEDIUM

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2025-67604
5.3 MEDIUM

A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, …

May 12, 2026
CVE-2025-53870
6.7 MEDIUM

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, …

May 12, 2026
CVE-2025-53680
6.7 MEDIUM

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 …

May 12, 2026
CVE-2026-8407
4.3 MEDIUM

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret …

May 12, 2026
CVE-2026-40300
6.5 MEDIUM

Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to …

May 12, 2026
CVE-2026-25431
5.3 MEDIUM

Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.

May 12, 2026
CVE-2026-20914
5.5 MEDIUM

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. …

May 12, 2026
CVE-2026-20905
6.6 MEDIUM

Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. …

May 12, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.