CVE Database

46686+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-45494
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

May 18, 2026
CVE-2026-45492
5.4 MEDIUM

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

May 18, 2026
CVE-2026-32849
5.5 MEDIUM

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as …

May 18, 2026
CVE-2026-32848
4.7 MEDIUM

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition …

May 18, 2026
CVE-2026-29965
6.1 MEDIUM

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or …

May 18, 2026
CVE-2026-29964
6.1 MEDIUM

HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript …

May 18, 2026
CVE-2026-8843
6.5 MEDIUM

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will …

May 18, 2026
CVE-2026-38719
6.2 MEDIUM

OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF message can supply …

May 18, 2026
CVE-2026-36438
5.3 MEDIUM

An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd

May 18, 2026
CVE-2026-20685
6.5 MEDIUM

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue …

May 18, 2026
CVE-2026-41949
5.9 MEDIUM

Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 …

May 18, 2026
CVE-2026-8802
4.3 MEDIUM

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The …

May 18, 2026
CVE-2026-41119
6.8 MEDIUM

Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to …

May 18, 2026
CVE-2026-6345
6.5 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate …

May 18, 2026
CVE-2026-6343
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public …

May 18, 2026
CVE-2026-6339
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member …

May 18, 2026
CVE-2026-5163
6.5 MEDIUM

Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of …

May 18, 2026
CVE-2026-3471
6.5 MEDIUM

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which …

May 18, 2026
CVE-2026-3117
6.5 MEDIUM

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to …

May 18, 2026
CVE-2026-28732
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated …

May 18, 2026
CVE-2026-6342
4.3 MEDIUM

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were …

May 18, 2026
CVE-2026-6341
4.3 MEDIUM

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can create issues or attach comments to which …

May 18, 2026
CVE-2026-6340
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to …

May 18, 2026
CVE-2026-3637
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an …

May 18, 2026
CVE-2026-2325
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API …

May 18, 2026
CVE-2026-28759
4.3 MEDIUM

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing …

May 18, 2026
CVE-2026-1631
5.4 MEDIUM

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube …

May 18, 2026
CVE-2026-8786
6.3 MEDIUM

A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the …

May 18, 2026
CVE-2026-8784
4.2 MEDIUM

A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink …

May 18, 2026
CVE-2026-8783
4.3 MEDIUM

A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabilityCheckResponse of the file ngap/dispatcher.go. Such manipulation leads to …

May 18, 2026
CVE-2026-8782
4.3 MEDIUM

A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/handler.go of the component NGAP Message …

May 18, 2026
CVE-2026-8781
4.3 MEDIUM

A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfiguration of the file ngap/handler.go. The manipulation …

May 18, 2026
CVE-2026-8780
4.3 MEDIUM

A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the file ngap/dispatcher.go of the component NGAP …

May 18, 2026
CVE-2026-8779
4.3 MEDIUM

A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument …

May 18, 2026
CVE-2026-8777
6.3 MEDIUM

A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. Performing …

May 18, 2026
CVE-2026-8774
6.3 MEDIUM

A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request …

May 18, 2026
CVE-2026-8773
4.7 MEDIUM

A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of …

May 18, 2026
CVE-2026-8772
4.7 MEDIUM

A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can …

May 18, 2026
CVE-2026-8769
4.3 MEDIUM

A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. …

May 17, 2026
CVE-2026-8767
5.0 MEDIUM

A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch …

May 17, 2026
CVE-2026-8766
4.3 MEDIUM

A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment …

May 17, 2026
CVE-2026-8765
4.3 MEDIUM

A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff …

May 17, 2026
CVE-2026-8754
6.3 MEDIUM

A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. …

May 17, 2026
CVE-2026-8753
6.3 MEDIUM

A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component …

May 17, 2026
CVE-2018-25337
4.3 MEDIUM

Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious …

May 17, 2026
CVE-2018-25336
5.3 MEDIUM

Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious …

May 17, 2026
CVE-2018-25334
5.4 MEDIUM

Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses …

May 17, 2026
CVE-2018-25331
6.1 MEDIUM

Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers …

May 17, 2026
CVE-2018-25327
5.3 MEDIUM

Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious …

May 17, 2026
CVE-2018-25324
6.2 MEDIUM

Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes …

May 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.