Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,535
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,241 - 2,260 of 13,065 CVEs
CVE-2026-46538 MEDIUM - 5.9

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not verify that a TASK_END message came from the device that originally received the ...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46416 MEDIUM - 6.3

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for multiple authenticated WebSocket connections. The handler stores per-connection protocol objects in mutab...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-45703 MEDIUM - 6.4

Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub

AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username

Vendor: pip
Product: asyncssh
Published: May 27, 2026
Source: GitHub
CVE-2026-47270 MEDIUM - 6.3

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb is a PAM module loaded into the host process (sudo, login, GDM, GNOME Shell). Display managers such as GDM run multiple concurrent authentication threads. Three functions used by the deny_remot...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44710 MEDIUM - 4.6

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed the return values of udisks_drive_get_serial(), udisks_drive_get_vendor(), and udisks_drive_get_model() directly to strcmp() without NULL checks. The GIO/UDisks API documentation st...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-21785 MEDIUM - 4.0

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

Vendor: HCLSoftware
Product: BigFix Remote Control Server
Published: May 27, 2026
Source: NVD

Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]

Vendor: composer
Product: symfony/http-kernel
Published: May 27, 2026
Source: GitHub

Symfony's Cas2Handler Derives CAS service URL from Client Host Header โ†’ Cross-Service Ticket Replay

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix

Vendor: composer
Product: symfony/cache
Published: May 27, 2026
Source: GitHub

Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names

Vendor: composer
Product: symfony/mime
Published: May 27, 2026
Source: GitHub

Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address

Vendor: composer
Product: symfony/mailer
Published: May 27, 2026
Source: GitHub
CVE-2026-9759 MEDIUM - 5.5

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

Vendor: wireshark
Product: wireshark
Published: May 27, 2026
Source: NVD
CVE-2026-48792 MEDIUM - 4.4

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ignores EACCES errors when opening /dev/input/event* nodes, causing pusb_has_virtual_input_device() to return 0 (no virtual devices found) even when every open() call failed due to...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-48066 MEDIUM - 5.7

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a process-wide static pointer that is written on every PAM invocation with the address of a stack-local variable. This violates the PAM re-entrancy requirement and creates a data rac...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-48065 MEDIUM - 6.7

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates heap memory proportional to n_devices, a count derived from libxml2 XPath evaluation of the config file, without first enforcing an upper bound. On 32-bit targets (armv7l, i686 -- ...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-47274 MEDIUM - 6.3

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb helper tools resolved external binaries through the PATH environment variable rather than using absolute paths. An attacker who can influence the process environment during PAM authent...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-47273 MEDIUM - 6.5

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath expressions from user-supplied identifiers (PAM username, service name) and device-supplied identifiers (USB device serial, model, vendor) to query /etc/pamusb.conf. These identifi...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-47271 MEDIUM - 5.1

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented out-of-memory guards for xmalloc(), xrealloc(), and xstrdup() using assert(data != NULL). The C standard specifies that all assert() expressions are compiled out when NDEBUG is de...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD