Total CVEs

132,988

Critical Severity

2,902

High Severity

10,432

Last 7 Days

2,058
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,081 - 2,100 of 29,393 CVEs
CVE-2026-40411 CRITICAL - 9.9

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: azure_virtual_network_gateway
Published: May 22, 2026
Source: NVD
CVE-2026-35430 HIGH - 8.8

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_privileged_identity_management
Published: May 22, 2026
Source: NVD
CVE-2026-33843 CRITICAL - 9.1

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: entra_id
Published: May 22, 2026
Source: NVD
CVE-2026-26147 HIGH - 7.7

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

Vendor: microsoft
Product: azure_stack_hci
Published: May 22, 2026
Source: NVD
CVE-2026-23663 HIGH - 7.5

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: global_secure_access
Published: May 22, 2026
Source: NVD
CVE-2026-23652 CRITICAL - 10.0

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: power_pages
Published: May 22, 2026
Source: NVD
CVE-2026-41076 HIGH - 8.1

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may ...

Published: May 22, 2026
Source: NVD
CVE-2026-41075 HIGH - 8.8

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them ...

Published: May 22, 2026
Source: NVD
CVE-2026-41074 HIGH - 7.1

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that use...

Published: May 22, 2026
Source: NVD
CVE-2026-41073 MEDIUM - 4.6

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output file, which can cause...

Published: May 22, 2026
Source: NVD
CVE-2026-41071 HIGH - 8.1

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructo...

Vendor: struktur
Product: libheif
Published: May 22, 2026
Source: NVD
CVE-2026-41069 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation ...

Vendor: struktur
Product: libheif
Published: May 22, 2026
Source: NVD

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administ...

Published: May 22, 2026
Source: NVD
CVE-2026-5843 HIGH - 8.2

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Pyth...

Published: May 22, 2026
Source: NVD
CVE-2026-5817 HIGH - 8.2

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled ...

Published: May 22, 2026
Source: NVD

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

Published: May 22, 2026
Source: NVD
CVE-2026-9291 HIGH - 7.1

Insecure deserialization in the job results processing component in Amazon Braket SDK beforeΒ 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to ama...

Published: May 22, 2026
Source: NVD
CVE-2026-6406 HIGH - 8.8

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker soc...

Vendor: docker
Product: docker_desktop
Published: May 22, 2026
Source: NVD

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation. This could b...

Published: May 22, 2026
Source: NVD
CVE-2026-40172 HIGH - 8.1

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, withou...

Published: May 22, 2026
Source: NVD