Total CVEs

132,996

Critical Severity

2,902

High Severity

10,437

Last 7 Days

2,056
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,161 - 2,180 of 29,401 CVEs
CVE-2021-21508 MEDIUM - 6.7

Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable applicat...

Published: May 22, 2026
Source: NVD
CVE-2026-9277 HIGH - 8.1

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.o...

Published: May 22, 2026
Source: NVD

vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the hist...

Published: May 22, 2026
Source: NVD
CVE-2026-8673 MEDIUM - 5.9

Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2026-8672 MEDIUM - 5.1

Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2026-8671 HIGH - 7.5

Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2026-8670 CRITICAL - 9.6

Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before 25.3.1.

Published: May 22, 2026
Source: NVD
CVE-2025-32749 HIGH - 7.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-32747 HIGH - 7.8

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-32746 MEDIUM - 5.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-32745 MEDIUM - 6.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-26483 HIGH - 8.2

Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to con...

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2026-44930 CRITICAL - 9.8

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Vendor: apache
Product: cxf
Published: May 22, 2026
Source: NVD
CVE-2026-44618 MEDIUM - 5.3

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Vendor: apache
Product: cxf
Published: May 22, 2026
Source: NVD
CVE-2026-44417 HIGH - 7.5

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, ...

Vendor: apache
Product: cxf
Published: May 22, 2026
Source: NVD
CVE-2026-47166 MEDIUM - 5.7

ImageMagick: Heap Buffer Over-Read in distributed pixel cache server

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 22, 2026
Source: GitHub
CVE-2026-47165 MEDIUM - 4.1

ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 22, 2026
Source: GitHub
CVE-2026-46693 MEDIUM - 4.1

ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 22, 2026
Source: GitHub
CVE-2026-46692 MEDIUM - 4.1

ImageMagick: Heap Buffer Over-Write in distributed pixel cache server

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 22, 2026
Source: GitHub
CVE-2026-5755 MEDIUM - 6.5

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, which allows authenticated users with file upload or posting permissions to cause a denial...

Vendor: mattermost
Product: mattermost_server
Published: May 22, 2026
Source: NVD