CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-8128
7.3 HIGH

A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of …

May 8, 2026
CVE-2026-8126
7.3 HIGH

A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulation of the argument …

May 8, 2026
CVE-2026-6411
7.3 HIGH

This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata …

May 7, 2026
CVE-2026-7541
7.5 HIGH

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with …

May 7, 2026
CVE-2026-41105
8.1 HIGH

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

May 7, 2026
CVE-2026-40213
7.4 HIGH

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token …

May 7, 2026
CVE-2026-35435
8.6 HIGH

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

May 7, 2026
CVE-2026-34327
8.2 HIGH

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

May 7, 2026
CVE-2026-33111
7.5 HIGH

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a …

May 7, 2026
CVE-2026-32207
8.8 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

May 7, 2026
CVE-2026-26164
7.5 HIGH

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a …

May 7, 2026
CVE-2026-26129
7.5 HIGH

Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network.

May 7, 2026
CVE-2026-8098
7.3 HIGH

A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. Such manipulation of the argument …

May 7, 2026
CVE-2026-42449
8.5 HIGH

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder …

May 7, 2026
CVE-2026-42047
8.6 HIGH

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that …

May 7, 2026
CVE-2026-43510
7.6 HIGH

manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another …

May 7, 2026
CVE-2026-42501
7.5 HIGH

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any …

May 7, 2026
CVE-2026-42499
7.5 HIGH

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

May 7, 2026
CVE-2026-42239
8.1 HIGH

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. …

May 7, 2026
CVE-2026-39836
7.5 HIGH

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

May 7, 2026
CVE-2026-39820
7.5 HIGH

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

May 7, 2026
CVE-2026-33814
7.5 HIGH

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

May 7, 2026
CVE-2026-33811
7.5 HIGH

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

May 7, 2026
CVE-2026-8083
7.3 HIGH

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation of the …

May 7, 2026
CVE-2026-44742
7.2 HIGH

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in …

May 7, 2026
CVE-2026-44244
7.8 HIGH

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. …

May 7, 2026
CVE-2026-44243
7.1 HIGH

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a …

May 7, 2026
CVE-2026-42284
8.1 HIGH

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" …

May 7, 2026
CVE-2026-42215
8.8 HIGH

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as …

May 7, 2026
CVE-2026-42214
7.8 HIGH

Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script without …

May 7, 2026
CVE-2026-41906
7.1 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope …

May 7, 2026
CVE-2026-41905
7.7 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via …

May 7, 2026
CVE-2026-41904
7.6 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store …

May 7, 2026
CVE-2026-7413
7.2 HIGH

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, …

May 7, 2026
CVE-2026-7821
7.4 HIGH

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted …

May 7, 2026
CVE-2026-6973
7.2 HIGH KEV

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code …

May 7, 2026
CVE-2026-5788
7.0 HIGH

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

May 7, 2026
CVE-2026-5787
8.9 HIGH

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain …

May 7, 2026
CVE-2026-5786
8.8 HIGH

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

May 7, 2026
CVE-2025-65122
7.5 HIGH

Regex Denial of Service in youtube-regex npm package through version 1.0.5.

May 7, 2026
CVE-2026-42011
7.4 HIGH

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name …

May 7, 2026
CVE-2026-41688
7.7 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but …

May 7, 2026
CVE-2026-41654
8.1 HIGH

Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any …

May 7, 2026
CVE-2026-41505
8.7 HIGH

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. …

May 7, 2026
CVE-2026-41422
8.3 HIGH

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() …

May 7, 2026
CVE-2025-63705
8.8 HIGH

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.

May 7, 2026
CVE-2026-41554
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS. This issue affects Bricks Builder: from n/a through …

May 7, 2026
CVE-2026-41490
8.3 HIGH

Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster Core version 1.13.1 and prior to Dagster libraries …

May 7, 2026
CVE-2026-30495
8.8 HIGH

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The …

May 7, 2026
CVE-2025-14341
8.3 HIGH

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. …

May 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.