CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-35194
8.1 HIGH

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute …

May 15, 2026
CVE-2026-2031

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose …

May 15, 2026
CVE-2026-8669
6.5 MEDIUM

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row …

May 15, 2026
CVE-2026-46483
3.6 LOW

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives …

May 15, 2026
CVE-2026-45736
4.4 MEDIUM

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a …

May 15, 2026
CVE-2026-39054
7.3 HIGH

Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process …

May 15, 2026
CVE-2026-39053
6.5 MEDIUM

Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry …

May 15, 2026
CVE-2026-39052
6.5 MEDIUM

Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the …

May 15, 2026
CVE-2026-38728
7.5 HIGH

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components

May 15, 2026
CVE-2026-34253
8.2 HIGH

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in …

May 15, 2026
CVE-2025-67437
6.5 MEDIUM

Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset.

May 15, 2026
CVE-2025-14972

* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be …

May 15, 2026
CVE-2026-46333
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory …

May 15, 2026
CVE-2026-7182

Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload …

May 15, 2026
CVE-2026-41553
10.0 CRITICAL

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated …

May 15, 2026
CVE-2026-41552
7.5 HIGH

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could …

May 15, 2026
CVE-2026-8503
6.5 MEDIUM

Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of …

May 15, 2026
CVE-2026-8454
5.3 MEDIUM

Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row …

May 15, 2026
CVE-2026-41971
5.5 MEDIUM

Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 15, 2026
CVE-2026-41970
6.8 MEDIUM

Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41969
6.2 MEDIUM

Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 15, 2026
CVE-2026-41968
5.9 MEDIUM

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41967
5.9 MEDIUM

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41966
5.6 MEDIUM

Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 15, 2026
CVE-2026-41965
5.6 MEDIUM

Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41964
8.4 HIGH

Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41963
2.8 LOW

Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41962
3.6 LOW

Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 15, 2026
CVE-2026-41961
5.9 MEDIUM

Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41960
5.8 MEDIUM

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-8425
4.3 MEDIUM

The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing …

May 15, 2026
CVE-2026-8398
9.8 CRITICAL KEV

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between …

May 15, 2026
CVE-2026-7563
4.3 MEDIUM

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and …

May 15, 2026
CVE-2026-7046
4.9 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions …

May 15, 2026
CVE-2026-6415
6.4 MEDIUM

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due …

May 15, 2026
CVE-2026-6403
7.5 HIGH

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation …

May 15, 2026
CVE-2026-6228
8.8 HIGH

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient …

May 15, 2026
CVE-2026-5229
9.8 CRITICAL

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting …

May 15, 2026
CVE-2026-4683
6.5 MEDIUM

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST …

May 15, 2026
CVE-2026-44088

SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader …

May 15, 2026
CVE-2026-8654

Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.

May 15, 2026
CVE-2026-6646
6.4 MEDIUM

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is …

May 15, 2026
CVE-2026-4094
8.1 HIGH

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the …

May 15, 2026
CVE-2026-41702
7.8 HIGH

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user …

May 15, 2026
CVE-2026-43490
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the …

May 15, 2026
CVE-2026-28761
8.1 HIGH

Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in …

May 15, 2026
CVE-2026-24662
5.4 MEDIUM

Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary …

May 15, 2026
CVE-2026-0481

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, …

May 15, 2026
CVE-2025-54518

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different …

May 15, 2026
CVE-2025-52532

A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could …

May 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.