Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,614
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,161 - 2,180 of 13,055 CVEs
CVE-2026-33462 MEDIUM - 4.6

A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifier. When an administrator subsequently attempts to delete this dashboard through the Kibana inte...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-47144 MEDIUM - 5.5

Shamefile has an arbitrary file read via shamefile.yaml in shame next

Vendor: pip
Product: shamefile
Published: May 28, 2026
Source: GitHub
CVE-2026-47128 MEDIUM - 6.1

nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

Vendor: rust
Product: nono-cli
Published: May 28, 2026
Source: GitHub
CVE-2026-47335 MEDIUM - 5.5

Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel panic.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47334 MEDIUM - 5.5

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47332 MEDIUM - 5.5

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent sl...

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47328 MEDIUM - 6.1

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and...

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47326 MEDIUM - 5.5

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-46526 MEDIUM - 5.0

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The m...

Vendor: LearningCircuit
Product: local-deep-research
Published: May 28, 2026
Source: NVD
CVE-2026-44394 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapp...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-43000 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token car...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-42999 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set fr...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-42998 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credent...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-46405 MEDIUM - 5.3

OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46380 MEDIUM - 6.7

compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-45307 MEDIUM - 6.1

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urljoin(request.host_url, target) before parsing, while the controller passed the raw target to redirect(...

Vendor: murtaza-nasir
Product: speakr
Published: May 28, 2026
Source: NVD

OpenBao's Inline Auth Incorrectly Redacted Headers

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub

compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC โ€” Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/mailtrap-mailer
Published: May 28, 2026
Source: GitHub

Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret โ€” Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/lox24-notifier
Published: May 28, 2026
Source: GitHub