Total CVEs

131,269

Critical Severity

2,778

High Severity

9,907

Last 7 Days

1,004
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,981 - 2,000 of 27,674 CVEs
CVE-2026-45158 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is f...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44478 HIGH - 7.5

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config overwrites. However, GET /v1/onboarding/config still ...

Vendor: hoppscotch
Product: hoppscotch
Published: May 13, 2026
Source: NVD
CVE-2026-44448 MEDIUM - 5.9

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44447 HIGH - 8.8

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44446 HIGH - 8.8

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 15.104.3 and 16...

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44445 MEDIUM - 6.5

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system, including sensitive configura...

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44442 CRITICAL - 9.9

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44441 MEDIUM - 5.0

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 15.106.0 and 16....

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44440 MEDIUM - 6.5

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files. This vulnera...

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacker who is able to create or edit an annotation guide on a task is able to add malicious JavaScript code, which will then run in the browser of anyone who opens this annotation guide...

Vendor: cvat-ai
Product: cvat
Published: May 13, 2026
Source: NVD
CVE-2026-44195 MEDIUM - 5.3

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword (...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44194 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formattin...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44193 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-42463 HIGH - 8.1

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoint...

Vendor: dataease
Product: SQLBot
Published: May 13, 2026
Source: NVD

Rejected reason: This CVE is a duplicate of another CVE.

Published: May 13, 2026
Source: NVD

Rejected reason: This CVE is a duplicate of another CVE.

Published: May 13, 2026
Source: NVD
CVE-2026-32993 HIGH - 8.3

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-32992 HIGH - 8.2

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-29205 HIGH - 8.6

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP add...

Published: May 13, 2026
Source: NVD