CVE Database

46686+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-41968
5.9 MEDIUM

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41967
5.9 MEDIUM

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41966
5.6 MEDIUM

Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 15, 2026
CVE-2026-41965
5.6 MEDIUM

Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41961
5.9 MEDIUM

Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-41960
5.8 MEDIUM

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

May 15, 2026
CVE-2026-8425
4.3 MEDIUM

The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing …

May 15, 2026
CVE-2026-7563
4.3 MEDIUM

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and …

May 15, 2026
CVE-2026-7046
4.9 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions …

May 15, 2026
CVE-2026-6415
6.4 MEDIUM

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due …

May 15, 2026
CVE-2026-4683
6.5 MEDIUM

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST …

May 15, 2026
CVE-2026-6646
6.4 MEDIUM

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is …

May 15, 2026
CVE-2026-24662
5.4 MEDIUM

Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary …

May 15, 2026
CVE-2026-8612
5.3 MEDIUM

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit …

May 15, 2026
CVE-2026-6811
5.9 MEDIUM

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of …

May 14, 2026
CVE-2026-45248
5.3 MEDIUM

Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can …

May 14, 2026
CVE-2026-44428
4.7 MEDIUM

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and …

May 14, 2026
CVE-2026-44661
4.7 MEDIUM

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a …

May 14, 2026
CVE-2026-44430
4.0 MEDIUM

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the Registry's HTTP-based …

May 14, 2026
CVE-2026-44429
5.4 MEDIUM

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue …

May 14, 2026
CVE-2026-8586
5.5 MEDIUM

Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security …

May 14, 2026
CVE-2026-8584
4.2 MEDIUM

Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform UI …

May 14, 2026
CVE-2026-8583
5.3 MEDIUM

Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain …

May 14, 2026
CVE-2026-8582
5.3 MEDIUM

Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a …

May 14, 2026
CVE-2026-8576
4.3 MEDIUM

Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted …

May 14, 2026
CVE-2026-8570
6.5 MEDIUM

Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

May 14, 2026
CVE-2026-8567
4.3 MEDIUM

Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via …

May 14, 2026
CVE-2026-8566
4.3 MEDIUM

Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a crafted …

May 14, 2026
CVE-2026-8565
4.7 MEDIUM

Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to …

May 14, 2026
CVE-2026-8564
4.2 MEDIUM

Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a …

May 14, 2026
CVE-2026-8563
4.3 MEDIUM

Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a crafted …

May 14, 2026
CVE-2026-8562
4.3 MEDIUM

Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

May 14, 2026
CVE-2026-8561
5.4 MEDIUM

Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

May 14, 2026
CVE-2026-8560
4.3 MEDIUM

Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds …

May 14, 2026
CVE-2026-8559
4.3 MEDIUM

Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via …

May 14, 2026
CVE-2026-8552
4.3 MEDIUM

Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write …

May 14, 2026
CVE-2026-8550
6.5 MEDIUM

Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially …

May 14, 2026
CVE-2026-8546
5.3 MEDIUM

Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer …

May 14, 2026
CVE-2026-8543
5.3 MEDIUM

Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in …

May 14, 2026
CVE-2026-8541
5.3 MEDIUM

Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially …

May 14, 2026
CVE-2026-8539
5.4 MEDIUM

Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a …

May 14, 2026
CVE-2026-8538
5.3 MEDIUM

Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform …

May 14, 2026
CVE-2026-8537
4.3 MEDIUM

Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

May 14, 2026
CVE-2026-8535
5.3 MEDIUM

Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer …

May 14, 2026
CVE-2026-8528
4.3 MEDIUM

Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass …

May 14, 2026
CVE-2026-8516
5.3 MEDIUM

Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific …

May 14, 2026
CVE-2026-43996
5.5 MEDIUM

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and …

May 14, 2026
CVE-2026-26062
6.5 MEDIUM

Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected …

May 14, 2026
CVE-2026-24000
5.3 MEDIUM

Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. …

May 14, 2026
CVE-2026-45148
4.3 MEDIUM

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate …

May 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.