Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,979
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,161 - 2,180 of 12,388 CVEs
CVE-2026-49366 HIGH - 7.8

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

Vendor: JetBrains
Product: IntelliJ IDEA
Published: May 29, 2026
Source: NVD
CVE-2026-47740 HIGH - 8.1

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete...

Vendor: shopperlabs
Product: shopper
Published: May 29, 2026
Source: NVD
CVE-2026-42941 HIGH - 8.3

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

Vendor: Danelec
Product: MacGregor Voyage Data Recorder (VDR) G4e
Published: May 29, 2026
Source: NVD
CVE-2026-42929 HIGH - 8.3

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

Vendor: Danelec
Product: MacGregor Voyage Data Recorder (VDR) G4e
Published: May 29, 2026
Source: NVD
CVE-2026-38739 HIGH - 7.1

ezsystems/ezpublish-legacy has a SQL injection in dfscleanup

Vendor: composer
Product: ezsystems/ezpublish-legacy
Published: May 29, 2026
Source: GitHub
CVE-2026-6824 HIGH - 8.4

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or...

Published: May 29, 2026
Source: NVD
CVE-2026-5768 HIGH - 8.8

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggeri...

Published: May 29, 2026
Source: NVD
CVE-2026-10108 HIGH - 7.5

xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated attackers to read arbitrary files outside the intended music directory by exploiting an incomplete path prefix check. Attackers can request files from sib...

Vendor: hanxi
Product: xiaomusic
Published: May 29, 2026
Source: NVD
CVE-2026-10107 HIGH - 7.7

MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token cookie and a URL whose domain matches the assembled allowlist. Attackers can bypass internal network protections ...

Vendor: jxxghp
Product: MoviePilot
Published: May 29, 2026
Source: NVD
CVE-2026-10105 HIGH - 8.3

agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickho...

Vendor: agno-agi
Product: agno
Published: May 29, 2026
Source: NVD
CVE-2026-47139 HIGH - 8.6

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes und...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47209 HIGH - 8.6

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inher...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47135 HIGH - 8.7

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbo...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-45742 HIGH - 7.5

Gotenberg has a Race Condition via Multipart `downloadFrom` Handling

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 29, 2026
Source: GitHub
CVE-2026-45741 HIGH - 7.5

Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 29, 2026
Source: GitHub
CVE-2026-44829 HIGH - 8.8

Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 29, 2026
Source: GitHub
CVE-2026-48501 HIGH - 7.4

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authenticatio...

Vendor: cli
Product: cli
Published: May 29, 2026
Source: NVD
CVE-2026-45662 HIGH - 8.8

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shE...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-39276 HIGH - 7.2

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or dir...

Published: May 29, 2026
Source: NVD
CVE-2026-35674 HIGH - 8.8

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and operator.admin scope r...

Vendor: OpenClaw
Product: OpenClaw
Published: May 29, 2026
Source: NVD