Total CVEs

132,098

Critical Severity

2,824

High Severity

10,104

Last 7 Days

1,581
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,301 - 2,320 of 28,503 CVEs
CVE-2026-8704 MEDIUM - 6.5

Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.

Published: May 15, 2026
Source: NVD
CVE-2026-8700 HIGH - 7.3

Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Published: May 15, 2026
Source: NVD
CVE-2026-8696 HIGH - 7.5

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability...

Vendor: radare
Product: radare2
Published: May 15, 2026
Source: NVD
CVE-2025-67031 MEDIUM - 6.3

ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant profile field processing subsystem. Certain field configurations accept values beginning with the prefix "func:" which are passed directly into ...

Published: May 15, 2026
Source: NVD
CVE-2026-8686 HIGH - 7.5

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1.

Vendor: freertos
Product: coremqtt
Published: May 15, 2026
Source: NVD
CVE-2026-4054 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled origin under a non-SVG Content-Type header (e.g. image...

Vendor: mattermost
Product: mattermost_server
Published: May 15, 2026
Source: NVD
CVE-2026-4053 LOW - 3.1

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. M...

Vendor: mattermost
Product: mattermost_server
Published: May 15, 2026
Source: NVD
CVE-2026-46408 HIGH - 7.6

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter the payment flow without verifying cart ownership. A logged-in attacker can therefore reuse another u...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2026-46407 HIGH - 8.1

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to load another administrator's REST API token list by supplying that user's admin_id. This ...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2026-46367 HIGH - 7.6

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject event handlers, stealing admin session cookies and achieving f...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46366 HIGH - 7.5

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46365 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE request with a valid sess...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46364 CRITICAL - 9.8

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/capt...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46363 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer param...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46362 MEDIUM - 6.5

phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs as authenticated user...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46361 MEDIUM - 6.9

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded payloads that bypass html_en...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46360 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG files with deeply ne...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46359 HIGH - 7.5

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break ou...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an authenticated SQL injection issue in the frontend user order history page in Vvveb CMS. A normal frontend user can log in and access /user/orders. The order_by and di...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an unauthenticated reflected cross-site scripting (XSS) issue in the public product return form in Vvveb CMS. The customer_order_id POST parameter is inserted into the O...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD