Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,578
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,001 - 2,020 of 28,420 CVEs
CVE-2026-45678 HIGH - 7.5

OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45679 MEDIUM - 6.5

OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45676 MEDIUM - 5.5

OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45031 MEDIUM - 5.3

ImageMagick: Policy Bypass in PSD decoder

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-42306 HIGH - 7.2

Docker: Race condition in docker cp allows bind mount redirection to host path

Vendor: go
Product: github.com/docker/docker
Published: May 18, 2026
Source: GitHub
CVE-2026-41568 MEDIUM - 6.1

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

Vendor: go
Product: github.com/docker/docker
Published: May 18, 2026
Source: GitHub

CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion

Vendor: pip
Product: cloakbrowser
Published: May 18, 2026
Source: GitHub
CVE-2026-45358 MEDIUM - 5.3

ImageMagick: Out-of-Bounds Read of a single byte in meta encoder

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45359 MEDIUM - 5.7

ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45719 MEDIUM - 6.5

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

Vendor: npm
Product: @budibase/server
Published: May 18, 2026
Source: GitHub
CVE-2026-41567 HIGH - 7.2

Docker: `PUT /containers/{id}/archive` executes container binary on the host

Vendor: go
Product: github.com/moby/moby/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45718 MEDIUM - 5.4

Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows

Vendor: npm
Product: budibase
Published: May 18, 2026
Source: GitHub
CVE-2026-45716 HIGH - 8.8

Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration

Vendor: npm
Product: @budibase/worker
Published: May 18, 2026
Source: GitHub
CVE-2026-45707 HIGH - 8.1

n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub

Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens

Vendor: composer
Product: sulu/sulu
Published: May 18, 2026
Source: GitHub
CVE-2026-45363 HIGH - 7.4

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

Vendor: rubygems
Product: jwt
Published: May 18, 2026
Source: GitHub
CVE-2026-45697 CRITICAL - 9.8

Formie: Pre-authenticated server-side template injection in Hidden fields

Vendor: composer
Product: verbb/formie
Published: May 18, 2026
Source: GitHub
CVE-2026-45327 HIGH - 8.2

TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection

Vendor: go
Product: github.com/DatanoiseTV/tinyice
Published: May 18, 2026
Source: GitHub
CVE-2026-8843 MEDIUM - 6.5

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "queryable_encrypted_range" indices. This issue a...

Published: May 18, 2026
Source: NVD

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in theΒ /api/v2/tenants/{tenant}/databases/{db}/...

Vendor: Chroma
Product: ChromaDB
Published: May 18, 2026
Source: NVD