Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
Showing 2,261 - 2,280 of 13,436 CVEs
CVE-2026-4390 MEDIUM - 5.4

A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the component Connection State Management. This manipulation causes use after free. The attack may be initiated remotely. Upgrading to version 3.13.8 is able to mitigate this issue. T...

Published: May 27, 2026
Source: NVD

Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal IP ranges, reserved hostnames, or URL schemes. Any authenticated user with builder-level access can supply an arbitra...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD
CVE-2026-48147 MEDIUM - 6.5

Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/matchers.ts route patterns are compiled into unanchored regular expressions and tested against ctx.request.url, which includes the full query string. T...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD

Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it directly to the query execution controller without additional validation. When combined with a REST datasource configured to target ...

Vendor: Budibase
Product: budibase
Published: May 27, 2026
Source: NVD
CVE-2026-45081 MEDIUM - 6.5

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employeesโ€™ leave details due to improper authorization checks. This vulnerability is fixed in 16.5.0.

Vendor: frappe
Product: hrms
Published: May 27, 2026
Source: NVD
CVE-2026-38808 MEDIUM - 5.3

SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.java components

Published: May 27, 2026
Source: NVD
CVE-2025-67903 MEDIUM - 5.3

Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.

Published: May 27, 2026
Source: NVD

Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions

Vendor: composer
Product: getkirby/cms
Published: May 27, 2026
Source: GitHub
CVE-2026-49054 MEDIUM - 4.3

Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.

Vendor: Mamunur Rashid
Product: The Post Grid
Published: May 27, 2026
Source: NVD
CVE-2026-45335 MEDIUM - 5.4

WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=InternoControle. Th...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 27, 2026
Source: NVD
CVE-2026-45027 MEDIUM - 5.9

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/Func...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 27, 2026
Source: NVD
CVE-2026-38931 MEDIUM - 5.4

A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.

Published: May 27, 2026
Source: NVD
CVE-2026-38930 MEDIUM - 6.5

OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the name cookie parameter.

Published: May 27, 2026
Source: NVD
CVE-2025-70116 MEDIUM - 4.3

A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV).

Published: May 27, 2026
Source: NVD
CVE-2025-68712 MEDIUM - 5.5

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authen...

Published: May 27, 2026
Source: NVD
CVE-2022-41656 MEDIUM - 4.3

Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from n/a through 2.1.2.

Vendor: Bizswoop
Product: Account Manager for WooCommerce
Published: May 27, 2026
Source: NVD

Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation โ†’ Off-Site //host URL Injection

Vendor: composer
Product: symfony/routing
Published: May 27, 2026
Source: GitHub
CVE-2026-9674 MEDIUM - 4.3

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.

Vendor: jenkins
Product: multijob
Published: May 27, 2026
Source: NVD
CVE-2026-49102 MEDIUM - 6.1

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

Vendor: Webmin
Product: Webmin
Published: May 27, 2026
Source: NVD
CVE-2026-49059 MEDIUM - 4.7

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.

Vendor: Facebook
Product: Facebook for WooCommerce
Published: May 27, 2026
Source: NVD