Total CVEs

131,397

Critical Severity

2,785

High Severity

9,965

Last 7 Days

1,111
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,101 - 2,120 of 27,802 CVEs
CVE-2026-46446 HIGH - 7.1

SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.

Vendor: Alinto
Product: SOGo
Published: May 14, 2026
Source: NVD
CVE-2026-46445 HIGH - 7.1

SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.

Vendor: Alinto
Product: SOGo
Published: May 14, 2026
Source: NVD
CVE-2026-46419 HIGH - 7.5

Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.

Vendor: Yubico
Product: webauthn-server-core
Published: May 14, 2026
Source: NVD
CVE-2026-44919 MEDIUM - 4.3

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

Vendor: OpenStack
Product: Ironic
Published: May 14, 2026
Source: NVD
CVE-2026-41281 MEDIUM - 4.8

Android App "ใ‚ใ‚“ใ—ใ‚“ใƒ•ใ‚ฃใƒซใ‚ฟใƒผ for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify communications transmitted in plaintext, potentially resulting in information disclosure or data ...

Vendor: KDDI CORPORATION
Product: ใ‚ใ‚“ใ—ใ‚“ใƒ•ใ‚ฃใƒซใ‚ฟใƒผ for au
Published: May 14, 2026
Source: NVD
CVE-2026-8500 CRITICAL - 9.8

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.

Published: May 13, 2026
Source: NVD
CVE-2026-32991 HIGH - 7.1

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

Vendor: WebPros
Product: cPanel, WP Squared, cPanel (CloudLinux 6, CentOS 6)
Published: May 13, 2026
Source: NVD
CVE-2026-29206 HIGH - 8.1

Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

Vendor: WebPros
Product: cPanel, WP Squared, cPanel (CloudLinux 6, CentOS 6)
Published: May 13, 2026
Source: NVD
CVE-2026-45158 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is f...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44478 HIGH - 7.5

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config overwrites. However, GET /v1/onboarding/config still ...

Vendor: hoppscotch
Product: hoppscotch
Published: May 13, 2026
Source: NVD
CVE-2026-44448 MEDIUM - 5.9

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44447 HIGH - 8.8

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44446 HIGH - 8.8

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 15.104.3 and 16...

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44445 MEDIUM - 6.5

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system, including sensitive configura...

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44442 CRITICAL - 9.9

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44441 MEDIUM - 5.0

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 15.106.0 and 16....

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44440 MEDIUM - 6.5

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files. This vulnera...

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacker who is able to create or edit an annotation guide on a task is able to add malicious JavaScript code, which will then run in the browser of anyone who opens this annotation guide...

Vendor: cvat-ai
Product: cvat
Published: May 13, 2026
Source: NVD
CVE-2026-44195 MEDIUM - 5.3

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword (...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44194 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formattin...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD