CVE Database

46686+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-20199
4.7 MEDIUM

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating …

May 20, 2026
CVE-2026-20171
6.8 MEDIUM

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could …

May 20, 2026
CVE-2026-8488
4.3 MEDIUM

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 …

May 20, 2026
CVE-2026-8487
6.5 MEDIUM

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

May 20, 2026
CVE-2026-8486
5.3 MEDIUM

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before …

May 20, 2026
CVE-2026-4293
5.3 MEDIUM

The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the …

May 20, 2026
CVE-2023-7346
4.0 MEDIUM

Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting …

May 20, 2026
CVE-2026-8485
5.9 MEDIUM

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

May 20, 2026
CVE-2026-21836
6.5 MEDIUM

The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining …

May 20, 2026
CVE-2026-5950
5.3 MEDIUM

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource …

May 20, 2026
CVE-2026-45498
4.0 MEDIUM KEV

Microsoft Defender Denial of Service Vulnerability

May 20, 2026
CVE-2026-45443
5.0 MEDIUM

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue …

May 20, 2026
CVE-2026-3592
5.3 MEDIUM

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will …

May 20, 2026
CVE-2026-27424
4.3 MEDIUM

Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo …

May 20, 2026
CVE-2026-27405
6.5 MEDIUM

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.

May 20, 2026
CVE-2026-24573
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0.

May 20, 2026
CVE-2025-31973
4.0 MEDIUM

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce …

May 20, 2026
CVE-2026-25602
4.4 MEDIUM

Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email …

May 20, 2026
CVE-2026-0857
6.0 MEDIUM

Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. This issue affects Meona Client Launcher Component: …

May 20, 2026
CVE-2026-6728
5.3 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes …

May 20, 2026
CVE-2026-44608
5.9 MEDIUM

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, …

May 20, 2026
CVE-2026-44390
5.3 MEDIUM

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name …

May 20, 2026
CVE-2026-42923
5.3 MEDIUM

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache …

May 20, 2026
CVE-2026-42534
5.3 MEDIUM

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. …

May 20, 2026
CVE-2026-35070
6.4 MEDIUM

Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged …

May 20, 2026
CVE-2026-32792
5.3 MEDIUM

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt …

May 20, 2026
CVE-2026-6405
4.3 MEDIUM

The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in …

May 20, 2026
CVE-2026-7385
5.8 MEDIUM

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API …

May 20, 2026
CVE-2026-6566
4.3 MEDIUM

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and …

May 20, 2026
CVE-2026-5776
6.1 MEDIUM

The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks

May 20, 2026
CVE-2026-44392
4.3 MEDIUM

Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may …

May 20, 2026
CVE-2026-2955
6.4 MEDIUM

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, …

May 20, 2026
CVE-2026-9056
5.4 MEDIUM

A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload …

May 20, 2026
CVE-2026-5075
4.3 MEDIUM

The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, …

May 20, 2026
CVE-2026-24215
5.7 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability …

May 20, 2026
CVE-2026-24208
5.3 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to …

May 20, 2026
CVE-2026-24160
5.5 MEDIUM

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit …

May 20, 2026
CVE-2026-24142
6.3 MEDIUM

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data …

May 20, 2026
CVE-2025-15369
5.3 MEDIUM

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

May 20, 2026
CVE-2026-8685
6.5 MEDIUM

The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. …

May 20, 2026
CVE-2026-8627
6.1 MEDIUM

The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is …

May 20, 2026
CVE-2026-8626
6.1 MEDIUM

The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient …

May 20, 2026
CVE-2026-8624
6.1 MEDIUM

The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 …

May 20, 2026
CVE-2026-8610
4.3 MEDIUM

The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to …

May 20, 2026
CVE-2026-8424
4.3 MEDIUM

The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to …

May 20, 2026
CVE-2026-8423
4.3 MEDIUM

The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This is due …

May 20, 2026
CVE-2026-8420
6.1 MEDIUM

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to …

May 20, 2026
CVE-2026-8419
4.3 MEDIUM

The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

May 20, 2026
CVE-2026-8418
4.3 MEDIUM

The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing or …

May 20, 2026
CVE-2026-8038
6.4 MEDIUM

The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions …

May 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.