CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-24199
4.7 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor …

May 26, 2026
CVE-2026-24198
5.6 MEDIUM

NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause …

May 26, 2026
CVE-2026-24197
6.5 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources …

May 26, 2026
CVE-2026-24182
6.5 MEDIUM

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might …

May 26, 2026
CVE-2025-33221
4.4 MEDIUM

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a …

May 26, 2026
CVE-2026-9565
6.3 MEDIUM

A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handler. Executing …

May 26, 2026
CVE-2026-8852
6.2 MEDIUM

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.

May 26, 2026
CVE-2026-48905
6.1 MEDIUM

Lack of input filtering leads to an XSS vector in the HTML filter code.

May 26, 2026
CVE-2026-48903
6.1 MEDIUM

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

May 26, 2026
CVE-2026-48900
4.3 MEDIUM

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

May 26, 2026
CVE-2026-48693
5.5 MEDIUM

FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' …

May 26, 2026
CVE-2026-47728
4.3 MEDIUM

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the …

May 26, 2026
CVE-2026-46431
4.3 MEDIUM

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless …

May 26, 2026
CVE-2026-46430
4.3 MEDIUM

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent …

May 26, 2026
CVE-2026-44723
5.0 MEDIUM

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four …

May 26, 2026
CVE-2026-44502
4.3 MEDIUM

Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. …

May 26, 2026
CVE-2026-44314
4.3 MEDIUM

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams …

May 26, 2026
CVE-2026-35220
4.3 MEDIUM

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

May 26, 2026
CVE-2026-30895
6.1 MEDIUM

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

May 26, 2026
CVE-2026-30894
6.1 MEDIUM

Lack of output escaping leads to a XSS vector in the content history component.

May 26, 2026
CVE-2026-25901
6.1 MEDIUM

Lack of output escaping leads to a XSS vector in the multilingual associations component.

May 26, 2026
CVE-2026-25900
6.1 MEDIUM

Lack of output escaping leads to a XSS vector in the feed modules.

May 26, 2026
CVE-2025-36221
5.3 MEDIUM

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from …

May 26, 2026
CVE-2025-36220
4.3 MEDIUM

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A …

May 26, 2026
CVE-2025-36148
5.4 MEDIUM

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows …

May 26, 2026
CVE-2025-36145
5.4 MEDIUM

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files …

May 26, 2026
CVE-2025-36126
6.4 MEDIUM

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. …

May 26, 2026
CVE-2025-14290
5.4 MEDIUM

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow …

May 26, 2026
CVE-2025-13755
5.5 MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files …

May 26, 2026
CVE-2026-48685
6.5 MEDIUM

FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the …

May 26, 2026
CVE-2026-48684
6.5 MEDIUM

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.cpp), the scope parsing loop (lines 224-229) …

May 26, 2026
CVE-2026-48683
6.5 MEDIUM

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) …

May 26, 2026
CVE-2026-46620
6.5 MEDIUM

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem …

May 26, 2026
CVE-2026-43936
4.3 MEDIUM

e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from …

May 26, 2026
CVE-2026-43934
6.5 MEDIUM

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to …

May 26, 2026
CVE-2026-38587
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated …

May 26, 2026
CVE-2026-41917
4.9 MEDIUM

OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying …

May 26, 2026
CVE-2026-41401
6.5 MEDIUM

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can …

May 26, 2026
CVE-2026-9542
6.3 MEDIUM

A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation …

May 26, 2026
CVE-2026-9541
5.3 MEDIUM

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File …

May 26, 2026
CVE-2026-9540
5.3 MEDIUM

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial …

May 26, 2026
CVE-2026-8174
5.7 MEDIUM

Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.

May 26, 2026
CVE-2026-48136
4.1 MEDIUM

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated …

May 26, 2026
CVE-2026-48135
5.3 MEDIUM

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

May 26, 2026
CVE-2026-48134
5.6 MEDIUM

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access …

May 26, 2026
CVE-2026-39642
5.3 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a …

May 26, 2026
CVE-2026-27427
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from …

May 26, 2026
CVE-2026-24638
4.3 MEDIUM

Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

May 26, 2026
CVE-2026-24590
5.3 MEDIUM

Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from …

May 26, 2026
CVE-2026-39655
5.3 MEDIUM

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

May 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.