Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,720
Quick preset (or use dates below)
Clear Filters
Showing 2,141 - 2,160 of 13,436 CVEs
CVE-2026-10008 MEDIUM - 6.5

Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: May 28, 2026
Source: NVD
CVE-2026-10004 MEDIUM - 6.5

Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: May 28, 2026
Source: NVD
CVE-2026-45410 MEDIUM - 5.3

TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an email address existed in the database, the backend performed a bcrypt password comparison before retur...

Vendor: mauriceboe
Product: TREK
Published: May 28, 2026
Source: NVD
CVE-2026-45023 MEDIUM - 5.4

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming any credits, regardless of the user's balance. The credit check that exists ...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: May 28, 2026
Source: NVD
CVE-2026-9646 MEDIUM - 6.1

A reflected cross-site scripting issue exists in URL handling.

Published: May 28, 2026
Source: NVD
CVE-2026-49095 MEDIUM - 6.5

Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a configuration override mechanism that is not adequately...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-49094 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kibana will consume exces...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-49093 MEDIUM - 6.3

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-46843 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46842 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46841 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability ...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46830 MEDIUM - 5.3

Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-42400 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and CPU resource consumpti...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-42399 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visualization expression co...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD

FUXA provides guest and invalid-token access to protected read APIs in secure mode

Vendor: npm
Product: fuxa-server
Published: May 28, 2026
Source: GitHub
CVE-2026-49130 MEDIUM - 5.3

Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attac...

Vendor: MusicPlayerDaemon
Product: MPD
Published: May 28, 2026
Source: NVD
CVE-2026-49129 MEDIUM - 5.8

Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allowing unauthenticated attackers to bypass the http/https scheme restriction by causing a malicious HTTP...

Vendor: MusicPlayerDaemon
Product: MPD
Published: May 28, 2026
Source: NVD
CVE-2026-42401 MEDIUM - 4.1

Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was not sufficiently sa...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-33464 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the Kibana process to exhaust available...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-33463 MEDIUM - 5.3

Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enabling an unauthenticated...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD