CVE Database

45744+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-43139
8.6 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). …

May 6, 2026
CVE-2026-43138
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: reset: gpio: suppress bind attributes in sysfs This is a special device that's created dynamically …

May 6, 2026
CVE-2026-43134
8.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption …

May 6, 2026
CVE-2026-43133
7.9 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 …

May 6, 2026
CVE-2026-43128
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix double dma_buf_unpin in failure path In ib_umem_dmabuf_get_pinned_with_dma_device(), the call to ib_umem_dmabuf_map_pages() can fail. …

May 6, 2026
CVE-2026-43126
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: mixer: oss: Add card disconnect checkpoints ALSA OSS mixer layer calls the kcontrol ops …

May 6, 2026
CVE-2025-31951
8.8 HIGH

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that …

May 6, 2026
CVE-2026-43646
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, …

May 6, 2026
CVE-2026-43120
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix double free related to rereg_user_mr If IB_MR_REREG_TRANS is set during rereg_user_mr, the umem …

May 6, 2026
CVE-2026-43116
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not …

May 6, 2026
CVE-2026-43113
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb() uses the firmware completion ID directly …

May 6, 2026
CVE-2026-43112
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or …

May 6, 2026
CVE-2026-43111
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: roccat: fix use-after-free in roccat_report_event roccat_report_event() iterates over the device->readers list without holding the …

May 6, 2026
CVE-2026-43110
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF events brcmf_fweh_handle_if_event() validates the firmware-provided interface index before …

May 6, 2026
CVE-2026-43106
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix incorrect dentry refcount in cachefiles_cull() The patch mentioned below changed cachefiles_bury_object() to expect …

May 6, 2026
CVE-2026-43101
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() We need to check __in6_dev_get() for possible …

May 6, 2026
CVE-2026-43099
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: fix null-ptr-deref in icmp_build_probe() ipv6_stub->ipv6_dev_find() may return ERR_PTR(-EAFNOSUPPORT) when the IPv6 stack is …

May 6, 2026
CVE-2026-43097
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: PCI: hv: Fix double ida_free in hv_pci_probe error path If hv_pci_probe() fails after storing the …

May 6, 2026
CVE-2026-43093
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xsk: tighten UMEM headroom validation to account for tailroom and min frame The current headroom …

May 6, 2026
CVE-2026-43091
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm: Wait for RCU readers during policy netns exit xfrm_policy_fini() frees the policy_bydst hash tables …

May 6, 2026
CVE-2026-43084
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: make hash table per queue Sharing a global hash table among all queues …

May 6, 2026
CVE-2026-43078
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl When page reassignment was added to …

May 6, 2026
CVE-2026-43076
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline data i_size during inode read When reading an inode from disk, ocfs2_validate_inode_block() …

May 6, 2026
CVE-2026-43075
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_write_end_inline KASAN reports a use-after-free write of 4086 bytes in …

May 6, 2026
CVE-2026-43074
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c …

May 6, 2026
CVE-2026-1719
7.5 HIGH

The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on …

May 6, 2026
CVE-2026-7841
8.8 HIGH

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on …

May 6, 2026
CVE-2026-7332
7.2 HIGH

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all …

May 6, 2026
CVE-2025-71256
7.5 HIGH

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71255
7.5 HIGH

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71254
7.5 HIGH

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71253
7.5 HIGH

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71252
7.5 HIGH

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

May 6, 2026
CVE-2025-71251
7.5 HIGH

In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

May 6, 2026
CVE-2026-40110
7.3 HIGH

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins …

May 5, 2026
CVE-2026-40075
7.5 HIGH

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is …

May 5, 2026
CVE-2026-40068
8.8 HIGH

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker …

May 5, 2026
CVE-2026-39852
8.2 HIGH

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between …

May 5, 2026
CVE-2026-39849
8.8 HIGH

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL …

May 5, 2026
CVE-2026-39383
7.2 HIGH

Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST …

May 5, 2026
CVE-2026-7857
7.2 HIGH

A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The …

May 5, 2026
CVE-2026-7856
7.2 HIGH

A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing …

May 5, 2026
CVE-2026-44331
8.1 HIGH

In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a …

May 5, 2026
CVE-2026-40280
7.5 HIGH

Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-sensitive …

May 5, 2026
CVE-2026-35397
8.8 HIGH

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated …

May 5, 2026
CVE-2026-34596
7.0 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When …

May 5, 2026
CVE-2026-34464
8.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed …

May 5, 2026
CVE-2026-34462
7.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR …

May 5, 2026
CVE-2026-34461
7.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The …

May 5, 2026
CVE-2026-34459
8.8 HIGH

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that …

May 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.