Total CVEs

148,841

Critical Severity

4,744

High Severity

16,941

Last 7 Days

3,089
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21,561 - 21,580 of 45,246 CVEs
CVE-2026-42880 CRITICAL - 9.6

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext...

Vendor: go
Product: github.com/argoproj/argo-cd/v3
Published: May 07, 2026
Source: GitHub

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.501 ยง6.9.5.1. The AMF does not check for ongoing N2 handover procedures before initiating a NAS Security Mode Command, an...

Vendor: go
Product: github.com/free5gc/amf
Published: May 07, 2026
Source: GitHub
CVE-2026-42081 MEDIUM - 6.1

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values, as mandated by 3GPP TS 33.501 ยง6.7.3.1. A malicious gNB can overwrite the AM...

Vendor: go
Product: github.com/free5gc/amf
Published: May 07, 2026
Source: GitHub

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated attacker, given another user's thread_id, can execute graph runs against the user's thread, read the use...

Vendor: pip
Product: aegra-api
Published: May 07, 2026
Source: GitHub

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed; Cookie, Proxy-Authoriz...

Vendor: maven
Product: com.microsoft.kiota:microsoft-kiota-abstractions
Published: May 07, 2026
Source: GitHub
CVE-2026-41050 CRITICAL - 9.9

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

Vendor: go
Product: github.com/rancher/fleet
Published: May 07, 2026
Source: GitHub
CVE-2026-25705 HIGH - 8.4

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A maliciou...

Vendor: go
Product: github.com/rancher/rancher
Published: May 07, 2026
Source: GitHub

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

Vendor: torproject
Product: Tor
Published: May 07, 2026
Source: NVD
CVE-2026-42597 MEDIUM - 5.9

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load ...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-42596 CRITICAL - 9.4

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as http://[::fff...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-42594 HIGH - 7.5

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handler returns ErrAsyncProcess and Echo recycles the context back to its sync.Pool. When a concurrent...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-42593 MEDIUM - 5.3

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampExpression=/path and watermarkSource=pdf + watermarkExpression...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-42592 MEDIUM - 5.3

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromium later performs its own DNS resolution when it n...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-42591 HIGH - 8.2

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely ...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-42590 HIGH - 8.2

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation on the server. ExifTool supports group-prefix...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-42589 CRITICAL - 9.8

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 07, 2026
Source: GitHub
CVE-2026-44484 CRITICAL - 9.8

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.

Vendor: pip
Product: pytorch-lightning
Published: May 07, 2026
Source: GitHub
CVE-2026-42587 HIGH - 7.5

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate en...

Vendor: maven
Product: io.netty:netty-codec-http
Published: May 07, 2026
Source: GitHub
CVE-2026-42586 MEDIUM - 6.8

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the R...

Vendor: maven
Product: io.netty:netty-codec-redis
Published: May 07, 2026
Source: GitHub
CVE-2026-42585 MEDIUM - 6.5

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

Vendor: maven
Product: io.netty:netty-codec-http
Published: May 07, 2026
Source: GitHub