CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-41498
3.3 LOW

Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to …

May 8, 2026
CVE-2026-8128
7.3 HIGH

A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of …

May 8, 2026
CVE-2026-8127
6.3 MEDIUM

A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users API Endpoint. …

May 8, 2026
CVE-2026-8126
7.3 HIGH

A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulation of the argument …

May 8, 2026
CVE-2026-6737

An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or …

May 8, 2026
CVE-2026-3508

An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read …

May 8, 2026
CVE-2026-8125
6.3 MEDIUM

A vulnerability was detected in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file sendMessage.php. The manipulation of the argument type/length/business …

May 8, 2026
CVE-2026-8124
3.3 LOW

A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads to allocation …

May 8, 2026
CVE-2026-8123
4.3 MEDIUM

A vulnerability was determined in Open5GS up to 2.7.7. This impacts the function ogs_sbi_discovery_option_add_snssais in the library /lib/sbi/message.c of the component NSSF. This manipulation causes …

May 8, 2026
CVE-2026-8122
4.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.7. This affects the function ogs_sbi_discovery_option_add_service_names in the library /lib/sbi/message.c of the component NSSF. The manipulation results …

May 8, 2026
CVE-2026-8121
4.3 MEDIUM

A vulnerability has been found in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_parse_plmn_list in the library /lib/sbi/conv.c of the component NSSF. …

May 8, 2026
CVE-2026-8120
4.3 MEDIUM

A flaw has been found in Open5GS up to 2.7.7. The affected element is the function nssf_nnrf_nsselection_handle_get_from_amf_or_vnssf of the file /src/nssf/nnssf-handler.c of the component NSSF. …

May 8, 2026
CVE-2026-8119
3.3 LOW

A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /lib/sbi/nghttp2-server.c of the component NSSF. Performing a manipulation …

May 8, 2026
CVE-2026-8117
4.3 MEDIUM

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unknown processing of the file /admin/index.php. Such manipulation of …

May 8, 2026
CVE-2026-8116
6.3 MEDIUM

A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of the file src/controllers/dxtController.ts. This manipulation of the argument …

May 8, 2026
CVE-2026-8115
5.3 MEDIUM

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST …

May 7, 2026
CVE-2026-6411
7.3 HIGH

This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata …

May 7, 2026
CVE-2026-42880
9.6 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a …

May 7, 2026
CVE-2026-2710

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 7, 2026
CVE-2026-8114
6.3 MEDIUM

A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON …

May 7, 2026
CVE-2026-8113
4.3 MEDIUM

A vulnerability was determined in 8421bit MiniClaw up to 43905b934cf76489ab28e4d17da28ee97970f91f. Affected by this vulnerability is the function isPathInside of the file src/kernel.ts of the component …

May 7, 2026
CVE-2026-8112
6.3 MEDIUM

A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the file src/kernel.ts. Performing a manipulation results in os …

May 7, 2026
CVE-2026-8106
6.1 MEDIUM

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter …

May 7, 2026
CVE-2026-8034
9.8 CRITICAL

A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting …

May 7, 2026
CVE-2026-7891

The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization misconfiguration. The VerySecureApp allows anonymous users of …

May 7, 2026
CVE-2026-7541
7.5 HIGH

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with …

May 7, 2026
CVE-2026-6736
6.5 MEDIUM

An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external …

May 7, 2026
CVE-2026-42826
10.0 CRITICAL

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

May 7, 2026
CVE-2026-41929
6.1 MEDIUM

Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulating …

May 7, 2026
CVE-2026-41928
5.3 MEDIUM

Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated attackers to retrieve the application's secret cron key. Attackers can …

May 7, 2026
CVE-2026-41105
8.1 HIGH

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

May 7, 2026
CVE-2026-40214
6.3 MEDIUM

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is …

May 7, 2026
CVE-2026-40213
7.4 HIGH

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token …

May 7, 2026
CVE-2026-35435
8.6 HIGH

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

May 7, 2026
CVE-2026-35428
9.6 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

May 7, 2026
CVE-2026-34327
8.2 HIGH

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

May 7, 2026
CVE-2026-33844
9.0 CRITICAL

Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

May 7, 2026
CVE-2026-33823
9.6 CRITICAL

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

May 7, 2026
CVE-2026-33111
7.5 HIGH

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a …

May 7, 2026
CVE-2026-33109
9.9 CRITICAL

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

May 7, 2026
CVE-2026-32207
8.8 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

May 7, 2026
CVE-2026-26164
7.5 HIGH

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a …

May 7, 2026
CVE-2026-26129
7.5 HIGH

Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network.

May 7, 2026
CVE-2026-8098
7.3 HIGH

A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. Such manipulation of the argument …

May 7, 2026
CVE-2026-8097
6.3 MEDIUM

A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /askquery.php. The manipulation of the argument …

May 7, 2026
CVE-2026-42449
8.5 HIGH

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder …

May 7, 2026
CVE-2026-42047
8.6 HIGH

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that …

May 7, 2026
CVE-2026-41692
4.7 MEDIUM

i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens …

May 7, 2026
CVE-2026-41691
6.5 MEDIUM

Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code …

May 7, 2026
CVE-2026-8142
6.5 MEDIUM

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions …

May 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.