CVE Find is a real-time vulnerability database indexing 349 029 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1601 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-42560 |
2026-05-09 06h16 +00:00 |
auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and... Authorization problems |
9.1 |
Critical |
|
CVE-2026-41705 |
2026-05-09 01h16 +00:00 |
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injec... |
8.6 |
High |
|
CVE-2026-44313 |
2026-05-09 00h16 +00:00 |
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and arc... Server-Side Request Forgery - SSRF |
9.1 |
Critical |
|
CVE-2026-42556 |
2026-05-08 23h16 +00:00 |
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any auth... Cross-site Scripting |
8.9 |
High |
|
CVE-2026-42454 |
2026-05-08 23h16 +00:00 |
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa... OS Command Injection |
9.9 |
Critical |
|
CVE-2026-42354 |
2026-05-08 23h16 +00:00 |
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version ... |
9.1 |
Critical |
|
CVE-2026-42352 |
2026-05-08 23h16 +00:00 |
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to... Server-Side Request Forgery - SSRF |
8.6 |
High |
|
CVE-2026-42302 |
2026-05-08 23h16 +00:00 |
FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-... Authorization problems |
9.8 |
Critical |
|
CVE-2026-42298 |
2026-05-08 23h16 +00:00 |
Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability... Code Injection |
10 |
Critical |
|
CVE-2026-42205 |
2026-05-08 22h16 +00:00 |
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken ... Authorization problems |
8.8 |
High |