CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-23827
7.5 HIGH

A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote …

May 12, 2026
CVE-2026-23826
7.5 HIGH

A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted …

May 12, 2026
CVE-2026-23825
7.5 HIGH

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages …

May 12, 2026
CVE-2026-23824
7.5 HIGH

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages …

May 12, 2026
CVE-2026-8431
7.2 HIGH

An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax. This issue …

May 12, 2026
CVE-2026-8430
8.1 HIGH

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to …

May 12, 2026
CVE-2026-8429
8.8 HIGH

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context …

May 12, 2026
CVE-2026-34684
7.8 HIGH

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 12, 2026
CVE-2026-34683
7.8 HIGH

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 12, 2026
CVE-2026-34682
7.8 HIGH

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 12, 2026
CVE-2026-34681
7.8 HIGH

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 12, 2026
CVE-2026-23823
7.2 HIGH

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could …

May 12, 2026
CVE-2026-23821
7.2 HIGH

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing …

May 12, 2026
CVE-2026-23820
7.2 HIGH

A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands …

May 12, 2026
CVE-2026-23819
8.8 HIGH

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript …

May 12, 2026
CVE-2026-44184
8.0 HIGH

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, …

May 12, 2026
CVE-2026-44167
7.5 HIGH

phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or …

May 12, 2026
CVE-2026-43929
8.2 HIGH

ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery …

May 12, 2026
CVE-2026-43892
8.8 HIGH

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is …

May 12, 2026
CVE-2026-43891
7.5 HIGH

changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from …

May 12, 2026
CVE-2026-42899
7.5 HIGH

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

May 12, 2026
CVE-2026-42896
7.8 HIGH

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-42893
7.4 HIGH

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

May 12, 2026
CVE-2026-42832
7.7 HIGH

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

May 12, 2026
CVE-2026-42831
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

May 12, 2026
CVE-2026-42825
7.0 HIGH

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-42141
7.7 HIGH

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side …

May 12, 2026
CVE-2026-41895
7.5 HIGH

changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates …

May 12, 2026
CVE-2026-41613
8.8 HIGH

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

May 12, 2026
CVE-2026-41611
7.8 HIGH

Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.

May 12, 2026
CVE-2026-41109
8.8 HIGH

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass …

May 12, 2026
CVE-2026-41107
7.4 HIGH

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

May 12, 2026
CVE-2026-41102
7.1 HIGH

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

May 12, 2026
CVE-2026-41101
7.1 HIGH

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

May 12, 2026
CVE-2026-41095
7.8 HIGH

Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-41094
8.8 HIGH

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.

May 12, 2026
CVE-2026-41088
7.8 HIGH

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-41086
8.8 HIGH

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

May 12, 2026
CVE-2026-40420
8.8 HIGH

Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-40419
7.8 HIGH

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-40418
7.8 HIGH

Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-40417
7.8 HIGH

Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-40415
8.1 HIGH

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

May 12, 2026
CVE-2026-40414
7.4 HIGH

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.

May 12, 2026
CVE-2026-40413
7.4 HIGH

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.

May 12, 2026
CVE-2026-40410
7.0 HIGH

Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-40408
7.8 HIGH

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-40407
7.8 HIGH

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

May 12, 2026
CVE-2026-40406
7.5 HIGH

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

May 12, 2026
CVE-2026-40405
7.5 HIGH

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

May 12, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.