CVE Find is a real-time vulnerability database indexing 350 083 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2173 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-44547 |
2026-05-12 23h16 +00:00 |
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058... Authorization problems |
9.6 |
Critical |
|
CVE-2026-42289 |
2026-05-12 23h16 +00:00 |
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user ... Improper Privilege ManagementAuthorization problemsCross-Site Request Forgery - CSRF |
8.8 |
High |
|
CVE-2026-42288 |
2026-05-12 23h16 +00:00 |
ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is ... Code Injection |
10 |
Critical |
|
CVE-2026-41901 |
2026-05-12 23h16 +00:00 |
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.... |
9 |
Critical |
|
CVE-2026-8449 |
2026-05-12 22h16 +00:00 |
Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allow... Overflow |
8.8 |
High |
|
CVE-2026-45227 |
2026-05-12 22h16 +00:00 |
Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that a... |
8.8 |
High |
|
CVE-2026-44262 |
2026-05-12 22h16 +00:00 |
Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when docume... Code Injection |
9.4 |
Critical |
|
CVE-2026-44015 |
2026-05-12 22h16 +00:00 |
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated us... Server-Side Request Forgery - SSRF |
8.5 |
High |
|
CVE-2026-43948 |
2026-05-12 22h16 +00:00 |
wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and g... Authorization problems |
9.9 |
Critical |
|
CVE-2026-42854 |
2026-05-12 22h16 +00:00 |
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 ... |
9.8 |
Critical |