CVE Database

54056+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-44195
5.3 MEDIUM

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously …

May 13, 2026
CVE-2026-45228
5.4 MEDIUM

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html …

May 13, 2026
CVE-2026-45054
4.9 MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-controlled …

May 13, 2026
CVE-2026-44381
5.3 MEDIUM

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters …

May 13, 2026
CVE-2026-44379
5.3 MEDIUM

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid …

May 13, 2026
CVE-2026-44376
6.1 MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic …

May 13, 2026
CVE-2026-44373
5.3 MEDIUM

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in …

May 13, 2026
CVE-2026-39428
4.8 MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeCart v6.x. An attacker with administrative privileges can …

May 13, 2026
CVE-2025-27852
5.0 MEDIUM

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an …

May 13, 2026
CVE-2026-42549
4.4 MEDIUM

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recursive: true) on a path built from the user-supplied …

May 13, 2026
CVE-2026-33381
5.9 MEDIUM

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds …

May 13, 2026
CVE-2026-33380
6.3 MEDIUM

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle …

May 13, 2026
CVE-2026-33378
6.5 MEDIUM

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to …

May 13, 2026
CVE-2026-28383
6.5 MEDIUM

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can …

May 13, 2026
CVE-2026-28380
6.5 MEDIUM

Any Editor could delete any snapshot, even if they have no access to read or write them.

May 13, 2026
CVE-2026-28379
6.5 MEDIUM

A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal …

May 13, 2026
CVE-2026-28376
6.5 MEDIUM

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory …

May 13, 2026
CVE-2026-28374
4.3 MEDIUM

Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.

May 13, 2026
CVE-2026-8496
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated …

May 13, 2026
CVE-2026-44248
5.3 MEDIUM

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any …

May 13, 2026
CVE-2026-42586
6.8 MEDIUM

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to …

May 13, 2026
CVE-2026-42585
6.5 MEDIUM

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is …

May 13, 2026
CVE-2026-42581
5.8 MEDIUM

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: …

May 13, 2026
CVE-2026-42580
6.5 MEDIUM

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This …

May 13, 2026
CVE-2026-41255
6.1 MEDIUM

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via …

May 13, 2026
CVE-2026-33584
5.3 MEDIUM

Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This …

May 13, 2026
CVE-2026-22677
6.5 MEDIUM

Hermes WebUI prior to 0.51.44 - Release T contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary …

May 13, 2026
CVE-2026-44581
4.7 MEDIUM

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces …

May 13, 2026
CVE-2026-44580
6.1 MEDIUM

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted …

May 13, 2026
CVE-2026-44003
5.3 MEDIUM

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code …

May 13, 2026
CVE-2026-44002
5.8 MEDIUM

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks …

May 13, 2026
CVE-2026-44000
6.5 MEDIUM

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the …

May 13, 2026
CVE-2026-44577
5.9 MEDIUM

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, …

May 13, 2026
CVE-2026-44576
5.4 MEDIUM

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable …

May 13, 2026
CVE-2026-2695
6.3 MEDIUM

A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated …

May 13, 2026
CVE-2024-48519
6.2 MEDIUM

Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRover, ADIS1647x Sensor component.

May 13, 2026
CVE-2026-8367
4.8 MEDIUM

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a …

May 13, 2026
CVE-2026-45740
5.3 MEDIUM

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors …

May 13, 2026
CVE-2026-45028
6.1 MEDIUM

Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props and slots …

May 13, 2026
CVE-2026-44665
6.1 MEDIUM

fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks …

May 13, 2026
CVE-2026-44664
6.1 MEDIUM

fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This …

May 13, 2026
CVE-2026-44479
5.5 MEDIUM

Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or …

May 13, 2026
CVE-2026-44458
4.3 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for …

May 13, 2026
CVE-2026-44457
5.3 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that …

May 13, 2026
CVE-2026-44456
6.5 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without …

May 13, 2026
CVE-2026-44455
4.7 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx …

May 13, 2026
CVE-2026-44431
5.3 MEDIUM

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward …

May 13, 2026
CVE-2026-44294
5.3 MEDIUM

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain …

May 13, 2026
CVE-2026-44292
5.3 MEDIUM

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object …

May 13, 2026
CVE-2026-44288
5.3 MEDIUM

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences …

May 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.