CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-8142
6.5 MEDIUM

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions …

May 7, 2026
CVE-2026-8088
3.3 LOW

A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation …

May 7, 2026
CVE-2026-8087
5.3 MEDIUM

A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of …

May 7, 2026
CVE-2026-43510
7.6 HIGH

manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another …

May 7, 2026
CVE-2026-42501
7.5 HIGH

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any …

May 7, 2026
CVE-2026-42499
7.5 HIGH

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

May 7, 2026
CVE-2026-42259

Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-beta.5, Saltcorn validates the post-login dest parameter with a …

May 7, 2026
CVE-2026-42241
5.3 MEDIUM

ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.0.1, DecimalConverter.ReadDecimal makes a stackalloc using what …

May 7, 2026
CVE-2026-42239
8.1 HIGH

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. …

May 7, 2026
CVE-2026-42225
5.9 MEDIUM

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_transport_tls) …

May 7, 2026
CVE-2026-39836
7.5 HIGH

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

May 7, 2026
CVE-2026-39826
6.1 MEDIUM

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the …

May 7, 2026
CVE-2026-39825
5.3 MEDIUM

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, …

May 7, 2026
CVE-2026-39823
6.1 MEDIUM

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert …

May 7, 2026
CVE-2026-39820
7.5 HIGH

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

May 7, 2026
CVE-2026-39819
5.3 MEDIUM

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the …

May 7, 2026
CVE-2026-39817
5.9 MEDIUM

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a …

May 7, 2026
CVE-2026-33814
7.5 HIGH

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

May 7, 2026
CVE-2026-33811
7.5 HIGH

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

May 7, 2026
CVE-2026-8086
5.3 MEDIUM

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument …

May 7, 2026
CVE-2026-8084
3.3 LOW

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Grid …

May 7, 2026
CVE-2026-8083
7.3 HIGH

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation of the …

May 7, 2026
CVE-2026-44742
7.2 HIGH

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in …

May 7, 2026
CVE-2026-44244
7.8 HIGH

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. …

May 7, 2026
CVE-2026-44243
7.1 HIGH

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a …

May 7, 2026
CVE-2026-42284
8.1 HIGH

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" …

May 7, 2026
CVE-2026-42215
8.8 HIGH

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as …

May 7, 2026
CVE-2026-42214
7.8 HIGH

Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script without …

May 7, 2026
CVE-2026-41906
7.1 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope …

May 7, 2026
CVE-2026-41905
7.7 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via …

May 7, 2026
CVE-2026-41904
7.6 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store …

May 7, 2026
CVE-2026-41903
5.4 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended …

May 7, 2026
CVE-2026-41902
9.1 CRITICAL

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random …

May 7, 2026
CVE-2026-41653

BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. An attacker may …

May 7, 2026
CVE-2026-8081
6.3 MEDIUM

A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API …

May 7, 2026
CVE-2026-37709
9.8 CRITICAL

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the …

May 7, 2026
CVE-2026-7415
9.8 CRITICAL

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the …

May 7, 2026
CVE-2026-7414
9.8 CRITICAL

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be …

May 7, 2026
CVE-2026-7413
7.2 HIGH

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, …

May 7, 2026
CVE-2026-7821
7.4 HIGH

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted …

May 7, 2026
CVE-2026-6973
7.2 HIGH KEV

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code …

May 7, 2026
CVE-2026-5788
7.0 HIGH

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

May 7, 2026
CVE-2026-5787
8.9 HIGH

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain …

May 7, 2026
CVE-2026-5786
8.8 HIGH

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

May 7, 2026
CVE-2026-36388
5.4 MEDIUM

A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to …

May 7, 2026
CVE-2026-36387
6.5 MEDIUM

A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file …

May 7, 2026
CVE-2026-36341
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on …

May 7, 2026
CVE-2025-65122
7.5 HIGH

Regex Denial of Service in youtube-regex npm package through version 1.0.5.

May 7, 2026
CVE-2025-63704
9.8 CRITICAL

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly …

May 7, 2026
CVE-2025-63703
9.8 CRITICAL

npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

May 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.