CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42052

Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted …

May 4, 2026
CVE-2026-41572
5.3 MEDIUM

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay …

May 4, 2026
CVE-2026-41571
9.4 CRITICAL

Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no …

May 4, 2026
CVE-2026-41471
7.5 HIGH

Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contain an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated …

May 4, 2026
CVE-2026-37459
7.5 HIGH

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

May 4, 2026
CVE-2026-32834
7.5 HIGH

Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows …

May 4, 2026
CVE-2026-29004
8.1 HIGH

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to …

May 4, 2026
CVE-2026-0073
8.8 HIGH

In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead …

May 4, 2026
CVE-2026-42812
9.9 CRITICAL

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to …

May 4, 2026
CVE-2026-42811
9.9 CRITICAL

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table …

May 4, 2026
CVE-2026-42810
9.9 CRITICAL

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same …

May 4, 2026
CVE-2026-42809
9.9 CRITICAL

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those …

May 4, 2026
CVE-2026-42440
7.5 HIGH

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before 2.5.9 before 3.0.0-M3 Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and …

May 4, 2026
CVE-2026-42376
9.8 CRITICAL

D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username …

May 4, 2026
CVE-2026-42375
9.8 CRITICAL

D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" …

May 4, 2026
CVE-2026-42374
9.8 CRITICAL

D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" …

May 4, 2026
CVE-2026-42373
9.8 CRITICAL

D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username …

May 4, 2026
CVE-2026-42372
8.8 HIGH

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username …

May 4, 2026
CVE-2026-42090
9.6 CRITICAL

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version …

May 4, 2026
CVE-2026-42080
4.6 MEDIUM

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary file write vulnerability via `save_generated_slides`. This issue has …

May 4, 2026
CVE-2026-42079
8.6 HIGH

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated …

May 4, 2026
CVE-2026-42078
4.6 MEDIUM

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. …

May 4, 2026
CVE-2026-42077
5.2 MEDIUM

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to …

May 4, 2026
CVE-2026-42076
9.8 CRITICAL

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute …

May 4, 2026
CVE-2026-42075
8.1 HIGH

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers …

May 4, 2026
CVE-2026-42027
9.8 CRITICAL

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loads a class by …

May 4, 2026
CVE-2026-40682
9.1 CRITICAL

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static …

May 4, 2026
CVE-2026-38669
6.1 MEDIUM

wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.

May 4, 2026
CVE-2026-37461
7.5 HIGH

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP …

May 4, 2026
CVE-2026-29514
8.8 HIGH

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to …

May 4, 2026
CVE-2026-26956
9.8 CRITICAL

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside …

May 4, 2026
CVE-2026-26332
9.8 CRITICAL

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue …

May 4, 2026
CVE-2026-25293
9.6 CRITICAL

Buffer overflow due to incorrect authorization in PLC FW

May 4, 2026
CVE-2026-25266
5.5 MEDIUM

Memory corruption while processing IOCTL command when device is in power-save state.

May 4, 2026
CVE-2026-24781
9.8 CRITICAL

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows …

May 4, 2026
CVE-2026-24120
9.8 CRITICAL

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to …

May 4, 2026
CVE-2026-24118
9.8 CRITICAL

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code …

May 4, 2026
CVE-2026-24082
7.8 HIGH

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

May 4, 2026
CVE-2025-47408
7.8 HIGH

Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

May 4, 2026
CVE-2025-47407
7.8 HIGH

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.

May 4, 2026
CVE-2025-47406
6.1 MEDIUM

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

May 4, 2026
CVE-2025-47405
7.8 HIGH

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

May 4, 2026
CVE-2025-47404
6.5 MEDIUM

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

May 4, 2026
CVE-2025-47403
6.5 MEDIUM

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

May 4, 2026
CVE-2025-47401
6.5 MEDIUM

Transient DOS when processing target power rate tables during channel configuration.

May 4, 2026
CVE-2026-40563
8.1 HIGH

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. …

May 4, 2026
CVE-2026-37458
6.5 MEDIUM

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying …

May 4, 2026
CVE-2026-36365
7.8 HIGH

An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and …

May 4, 2026
CVE-2025-70071
5.9 MEDIUM

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()

May 4, 2026
CVE-2026-6501

Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5.

May 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.