CVE Database

54056+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-41519
4.2 MEDIUM

Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but …

May 7, 2026
CVE-2025-67202
6.1 MEDIUM

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

May 7, 2026
CVE-2026-41685
4.3 MEDIUM

Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the …

May 7, 2026
CVE-2026-41684
6.5 MEDIUM

Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back …

May 7, 2026
CVE-2026-41648
5.0 MEDIUM

Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files …

May 7, 2026
CVE-2026-41647
6.5 MEDIUM

Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause …

May 7, 2026
CVE-2026-5791
6.5 MEDIUM

Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

May 7, 2026
CVE-2026-8080
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A …

May 7, 2026
CVE-2026-33589
6.5 MEDIUM

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the …

May 7, 2026
CVE-2026-27415
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affects BEAR: from n/a through 1.1.5.

May 7, 2026
CVE-2026-44407
4.7 MEDIUM

A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.

May 7, 2026
CVE-2026-27421
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: …

May 7, 2026
CVE-2026-27416
5.3 MEDIUM

Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.

May 7, 2026
CVE-2026-27329
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: …

May 7, 2026
CVE-2026-25468
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects …

May 7, 2026
CVE-2026-25436
5.3 MEDIUM

Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before …

May 7, 2026
CVE-2025-68604
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGraphQL: from n/a through 2.5.3.

May 7, 2026
CVE-2025-66105
5.3 MEDIUM

Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket …

May 7, 2026
CVE-2025-62127
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS. This issue affects WEN Logo …

May 7, 2026
CVE-2025-2514
5.3 MEDIUM

Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage …

May 7, 2026
CVE-2026-44406
5.7 MEDIUM

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, …

May 7, 2026
CVE-2026-8063
6.5 MEDIUM

An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects …

May 7, 2026
CVE-2026-41413
5.0 MEDIUM

Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a …

May 7, 2026
CVE-2026-6214
6.5 MEDIUM

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function …

May 7, 2026
CVE-2026-42194
6.8 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes …

May 7, 2026
CVE-2026-41671
6.8 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every request, regardless …

May 7, 2026
CVE-2026-41662
5.2 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role leaves zero …

May 7, 2026
CVE-2026-41661
6.1 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admidio user's browser through a …

May 7, 2026
CVE-2026-41658
6.5 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive operations (delete, retire, reinstate) only in …

May 7, 2026
CVE-2026-41657
4.9 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker permission check (isAdministratorUsers(), requiring only rol_edit_user=true) than the …

May 7, 2026
CVE-2026-41656
4.5 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type …

May 7, 2026
CVE-2026-41655
6.5 MEDIUM

Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template POST parameter is a safe …

May 7, 2026
CVE-2026-41004
4.4 MEDIUM

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from …

May 7, 2026
CVE-2026-40004
5.5 MEDIUM

There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.

May 7, 2026
CVE-2026-4807
6.5 MEDIUM

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed …

May 7, 2026
CVE-2026-6222
5.3 MEDIUM

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method …

May 7, 2026
CVE-2026-40003
5.1 MEDIUM

ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB …

May 7, 2026
CVE-2026-41484
5.3 MEDIUM

OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to the configured …

May 6, 2026
CVE-2026-41483
5.9 MEDIUM

OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM instance …

May 6, 2026
CVE-2026-41417
5.3 MEDIUM

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors …

May 6, 2026
CVE-2026-41310
5.3 MEDIUM

OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cache accepts unbounded key growth derived from …

May 6, 2026
CVE-2026-40296
5.4 MEDIUM

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The HTML writer skips htmlspecialchars escaping when a cell's formatted value differs from …

May 6, 2026
CVE-2026-3291
5.5 MEDIUM

Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is …

May 6, 2026
CVE-2026-40251
6.5 MEDIUM

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated …

May 6, 2026
CVE-2026-40243
4.8 MEDIUM

Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow …

May 6, 2026
CVE-2026-40197
6.5 MEDIUM

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated …

May 6, 2026
CVE-2026-40195
6.5 MEDIUM

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated …

May 6, 2026
CVE-2026-8033
5.3 MEDIUM

A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ of the component Response …

May 6, 2026
CVE-2026-44117
5.8 MEDIUM

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending …

May 6, 2026
CVE-2026-44111
4.3 MEDIUM

OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the …

May 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.