Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,568
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,041 - 2,060 of 28,420 CVEs
CVE-2026-41947 HIGH - 7.4

Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-39079 HIGH - 7.5

An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components

Published: May 18, 2026
Source: NVD
CVE-2026-26462 HIGH - 7.3

Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary o...

Published: May 18, 2026
Source: NVD

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object (rather than a String) to Faraday::Connection#build_exclusive_url. This...

Vendor: rubygems
Product: faraday
Published: May 18, 2026
Source: GitHub

Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass

Vendor: npm
Product: neotoma
Published: May 18, 2026
Source: GitHub
CVE-2026-45627 HIGH - 8.2

Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45626 MEDIUM - 6.3

Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45625 CRITICAL - 9.9

Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45135 HIGH - 8.1

Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45620 MEDIUM - 5.3

AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`

Vendor: composer
Product: WWBN/AVideo
Published: May 18, 2026
Source: GitHub
CVE-2026-45609 HIGH - 7.2

Spring AI MCP Security: Unvalidated URL Fetching (SSRF)

Vendor: maven
Product: org.springaicommunity:mcp-client-security
Published: May 18, 2026
Source: GitHub
CVE-2026-46510 HIGH - 8.2

form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys

Vendor: npm
Product: form-data-objectizer
Published: May 18, 2026
Source: GitHub
CVE-2026-45582 MEDIUM - 6.5

n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub
CVE-2026-42009 HIGH - 7.5

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This cou...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 18, 2026
Source: NVD
CVE-2026-8803 LOW - 3.7

A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have...

Published: May 18, 2026
Source: NVD
CVE-2026-7304 CRITICAL - 9.8

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD
CVE-2026-7302 CRITICAL - 9.1

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD
CVE-2026-7301 CRITICAL - 9.8

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD

Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash

Published: May 18, 2026
Source: NVD
CVE-2026-8802 MEDIUM - 4.3

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identifie...

Published: May 18, 2026
Source: NVD