Total CVEs

131,397

Critical Severity

2,785

High Severity

9,965

Last 7 Days

1,108
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,121 - 2,140 of 27,802 CVEs
CVE-2026-44193 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-42463 HIGH - 8.1

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoint...

Vendor: dataease
Product: SQLBot
Published: May 13, 2026
Source: NVD

Rejected reason: This CVE is a duplicate of another CVE.

Published: May 13, 2026
Source: NVD

Rejected reason: This CVE is a duplicate of another CVE.

Published: May 13, 2026
Source: NVD
CVE-2026-32993 HIGH - 8.3

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-32992 HIGH - 8.2

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-29205 HIGH - 8.6

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP add...

Published: May 13, 2026
Source: NVD
CVE-2026-45714 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using th...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45708 HIGH - 7.2

CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php โ€ฆ ?> into the Invoice Editor. The next time any admin clicks Print on any order, the rendered template is written to files/print.<md5>.php. files/.htaccess ships an expl...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45229 HIGH - 8.8

Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to perm...

Vendor: Cp0204
Product: quark-auto-save
Published: May 13, 2026
Source: NVD
CVE-2026-45228 MEDIUM - 5.4

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through t...

Vendor: Cp0204
Product: quark-auto-save
Published: May 13, 2026
Source: NVD
CVE-2026-45055 HIGH - 8.1

CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x โ€“ 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordReq...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45054 MEDIUM - 4.9

CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-controlled $_GET['sort'] array without column or direction validation. Both the column key...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45053 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the we...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD

EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly into SQL queries via str_replace without any sanitization, enabling SQL injection through query par...

Vendor: phili67
Product: ecclesiacrm
Published: May 13, 2026
Source: NVD
CVE-2026-44381 MEDIUM - 5.3

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values from request parameters ...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD
CVE-2026-44380 HIGH - 7.2

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within th...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD
CVE-2026-44379 MEDIUM - 5.3

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID values, potentially causing integrity issues or u...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD
CVE-2026-44377 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty templa...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD