Total CVEs

132,988

Critical Severity

2,902

High Severity

10,432

Last 7 Days

2,059
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,061 - 2,080 of 29,393 CVEs
CVE-2026-9294 HIGH - 8.8

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack rem...

Published: May 23, 2026
Source: NVD
CVE-2026-9284 HIGH - 8.2

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` end...

Published: May 23, 2026
Source: NVD
CVE-2026-6898 HIGH - 8.8

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Sub...

Published: May 23, 2026
Source: NVD
CVE-2026-6897 HIGH - 8.8

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attack...

Published: May 23, 2026
Source: NVD
CVE-2026-6895 HIGH - 8.8

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns...

Published: May 23, 2026
Source: NVD
CVE-2026-6419 HIGH - 8.8

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscribe...

Published: May 23, 2026
Source: NVD
CVE-2026-47124 MEDIUM - 6.5

Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 23, 2026
Source: GitHub
CVE-2026-46716 CRITICAL - 9.9

Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 23, 2026
Source: GitHub
CVE-2026-47125 HIGH - 8.8

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in every project's compose file, is missing an admin a...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 23, 2026
Source: GitHub
CVE-2026-47157 MEDIUM - 6.5

aiograpi: Unsafe signup challenge path handling

Vendor: pip
Product: aiograpi
Published: May 23, 2026
Source: GitHub

Parse Server: Pre-authentication denial of service via client version header regex backtracking

Vendor: npm
Product: parse-server
Published: May 23, 2026
Source: GitHub
CVE-2026-47120 MEDIUM - 5.4

Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 23, 2026
Source: GitHub
CVE-2026-46717 HIGH - 8.5

Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 23, 2026
Source: GitHub
CVE-2026-47280 CRITICAL - 10.0

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_resource_manager
Published: May 22, 2026
Source: NVD
CVE-2026-45659 HIGH - 8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: sharepoint_server
Published: May 22, 2026
Source: NVD
CVE-2026-42901 CRITICAL - 10.0

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: entra_id
Published: May 22, 2026
Source: NVD
CVE-2026-42827 MEDIUM - 6.5

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: 365_copilot
Published: May 22, 2026
Source: NVD
CVE-2026-41104 CRITICAL - 10.0

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: planetary_computer
Published: May 22, 2026
Source: NVD
CVE-2026-41090 CRITICAL - 9.3

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: 365_copilot
Published: May 22, 2026
Source: NVD
CVE-2026-40412 CRITICAL - 10.0

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: azure_orbital_spatio
Published: May 22, 2026
Source: NVD