CVE Database

137172+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9306
3.7 LOW

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney …

May 23, 2026
CVE-2026-9305
6.3 MEDIUM

A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component …

May 23, 2026
CVE-2026-9304
5.0 MEDIUM

A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the …

May 23, 2026
CVE-2026-9303
4.3 MEDIUM

A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible …

May 23, 2026
CVE-2026-9302
6.3 MEDIUM

A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of the component VpsTest Console. …

May 23, 2026
CVE-2026-9301
6.3 MEDIUM

A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results …

May 23, 2026
CVE-2026-9300
6.3 MEDIUM

A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to …

May 23, 2026
CVE-2026-46300
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to …

May 23, 2026
CVE-2026-43503

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail …

May 23, 2026
CVE-2026-9299
6.3 MEDIUM

A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation …

May 23, 2026
CVE-2026-9298
6.3 MEDIUM

A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality of the component PathSwitchRequest Handler. The manipulation …

May 23, 2026
CVE-2026-9297
6.3 MEDIUM

A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. …

May 23, 2026
CVE-2026-9296
6.3 MEDIUM

A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request Handler. Executing …

May 23, 2026
CVE-2026-9295
8.8 HIGH

A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. …

May 23, 2026
CVE-2026-9294
8.8 HIGH

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. …

May 23, 2026
CVE-2026-9284
8.2 HIGH

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and …

May 23, 2026
CVE-2026-6898
8.8 HIGH

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all …

May 23, 2026
CVE-2026-6897
8.8 HIGH

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all …

May 23, 2026
CVE-2026-6895
8.8 HIGH

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including …

May 23, 2026
CVE-2026-6419
8.8 HIGH

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to …

May 23, 2026
CVE-2026-47280
10.0 CRITICAL

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026
CVE-2026-45659
8.8 HIGH KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

May 22, 2026
CVE-2026-42901
10.0 CRITICAL

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026
CVE-2026-42827
6.5 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

May 22, 2026
CVE-2026-41149

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through …

May 22, 2026
CVE-2026-41148

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through …

May 22, 2026
CVE-2026-41104
10.0 CRITICAL

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

May 22, 2026
CVE-2026-41090
9.3 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

May 22, 2026
CVE-2026-40412
10.0 CRITICAL

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

May 22, 2026
CVE-2026-40411
9.9 CRITICAL

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

May 22, 2026
CVE-2026-35430
8.8 HIGH

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

May 22, 2026
CVE-2026-33843
9.1 CRITICAL

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026
CVE-2026-26147
7.7 HIGH

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

May 22, 2026
CVE-2026-23663
7.5 HIGH

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026
CVE-2026-23652
10.0 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

May 22, 2026
CVE-2026-41147
8.7 HIGH

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization …

May 22, 2026
CVE-2026-41076
8.1 HIGH

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass …

May 22, 2026
CVE-2026-41075
8.8 HIGH

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An …

May 22, 2026
CVE-2026-41074
7.1 HIGH

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who …

May 22, 2026
CVE-2026-41073
4.6 MEDIUM

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. …

May 22, 2026
CVE-2026-41071
8.1 HIGH

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box …

May 22, 2026
CVE-2026-41069
6.5 MEDIUM

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds …

May 22, 2026
CVE-2026-40864
5.4 MEDIUM

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately …

May 22, 2026
CVE-2026-3294

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the …

May 22, 2026
CVE-2026-5843
8.2 HIGH

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories …

May 22, 2026
CVE-2026-5817
8.2 HIGH

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to …

May 22, 2026
CVE-2026-40610
5.5 MEDIUM

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging …

May 22, 2026
CVE-2026-40607

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of …

May 22, 2026
CVE-2026-40598

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's …

May 22, 2026
CVE-2026-40597

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker …

May 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.