Total CVEs

131,459

Critical Severity

2,797

High Severity

9,990

Last 7 Days

1,145
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,181 - 2,200 of 27,864 CVEs
CVE-2026-44195 MEDIUM - 5.3

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword (...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44194 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formattin...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44193 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-42463 HIGH - 8.1

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoint...

Vendor: dataease
Product: SQLBot
Published: May 13, 2026
Source: NVD

Rejected reason: This CVE is a duplicate of another CVE.

Published: May 13, 2026
Source: NVD

Rejected reason: This CVE is a duplicate of another CVE.

Published: May 13, 2026
Source: NVD
CVE-2026-32993 HIGH - 8.3

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-32992 HIGH - 8.2

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-29205 HIGH - 8.6

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP add...

Published: May 13, 2026
Source: NVD
CVE-2026-45714 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using th...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45708 HIGH - 7.2

CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php โ€ฆ ?> into the Invoice Editor. The next time any admin clicks Print on any order, the rendered template is written to files/print.<md5>.php. files/.htaccess ships an expl...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45229 HIGH - 8.8

Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to perm...

Vendor: Cp0204
Product: quark-auto-save
Published: May 13, 2026
Source: NVD
CVE-2026-45228 MEDIUM - 5.4

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through t...

Vendor: Cp0204
Product: quark-auto-save
Published: May 13, 2026
Source: NVD
CVE-2026-45055 HIGH - 8.1

CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x โ€“ 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordReq...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45054 MEDIUM - 4.9

CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-controlled $_GET['sort'] array without column or direction validation. Both the column key...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45053 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the we...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD

EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly into SQL queries via str_replace without any sanitization, enabling SQL injection through query par...

Vendor: phili67
Product: ecclesiacrm
Published: May 13, 2026
Source: NVD
CVE-2026-44381 MEDIUM - 5.3

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values from request parameters ...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD
CVE-2026-44380 HIGH - 7.2

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within th...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD