Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,568
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,021 - 2,040 of 28,420 CVEs
CVE-2026-41085 HIGH - 8.8

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces.

Published: May 18, 2026
Source: NVD
CVE-2026-38719 MEDIUM - 6.2

OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF message can supply an attacker-controlled item_count value that is not consistently v...

Published: May 18, 2026
Source: NVD
CVE-2026-45325 HIGH - 8.2

@tmlmobilidade/utils has prototype pollution in its setValueAtPath

Vendor: npm
Product: @tmlmobilidade/utils
Published: May 18, 2026
Source: GitHub
CVE-2026-45302 HIGH - 8.2

parse-nested-form-data has Prototype Pollution via `__proto__` in FormData field names

Vendor: npm
Product: parse-nested-form-data
Published: May 18, 2026
Source: GitHub
CVE-2026-45300 HIGH - 7.4

async-http-client: Cookie header not stripped on cross-origin redirect

Vendor: maven
Product: org.asynchttpclient:async-http-client
Published: May 18, 2026
Source: GitHub
CVE-2026-45298 HIGH - 8.6

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that ...

Vendor: go
Product: github.com/amir20/dozzle
Published: May 18, 2026
Source: GitHub
CVE-2026-46385 HIGH - 7.5

iskorotkov/avro: CPU Exhaustion in Decoder

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45270 HIGH - 8.7

CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-46384 HIGH - 7.5

iskorotkov/avro: Integer Overflow in Decoder

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45149 MEDIUM - 6.5

brace-expansion: Large numeric range defeats documented `max` DoS protection

Vendor: npm
Product: brace-expansion
Published: May 18, 2026
Source: GitHub
CVE-2026-45139 MEDIUM - 6.5

CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-36438 MEDIUM - 5.3

An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd

Published: May 18, 2026
Source: NVD
CVE-2026-20685 MEDIUM - 6.5

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

Vendor: Apple
Product: Private Cloud Compute Server Software
Published: May 18, 2026
Source: NVD
CVE-2025-57282 HIGH - 8.8

ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.

Published: May 18, 2026
Source: NVD
CVE-2025-56352 HIGH - 7.5

In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length Client ID while CleanSession is set to 0, the broker correctly replies with a CONNACK return code 0x02...

Published: May 18, 2026
Source: NVD
CVE-2026-45138 MEDIUM - 5.4

CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-45660 MEDIUM - 5.4

Statamic CMS: Server-Side Request Forgery via Glide

Vendor: composer
Product: statamic/cms
Published: May 18, 2026
Source: GitHub
CVE-2026-42326 MEDIUM - 5.1

ImageMagick: Heap Buffer Over-Read in IPTC encoder

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-41949 MEDIUM - 5.9

Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-41948 HIGH - 7.7

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unenc...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD