Total CVEs

133,033

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,072
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,301 - 2,320 of 29,438 CVEs
CVE-2026-22678 MEDIUM - 5.4

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized...

Vendor: Webmin
Product: Webmin
Published: May 21, 2026
Source: NVD
CVE-2026-46703 CRITICAL - 9.6

Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host

Vendor: pip
Product: boxlite
Published: May 21, 2026
Source: GitHub
CVE-2026-46695 CRITICAL - 10.0

BoxLite: Permission Bypass Allows Modification of Read-Only Files

Vendor: pip
Product: boxlite
Published: May 21, 2026
Source: GitHub

@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty

Vendor: npm
Product: @nevware21/ts-utils
Published: May 21, 2026
Source: GitHub

containerd user ID handling bypass allows runAsNonRoot evasion

Vendor: go
Product: github.com/containerd/containerd
Published: May 21, 2026
Source: GitHub
CVE-2026-46679 HIGH - 7.5

js-libp2p: Memory DoS via subscription flood of unique topics

Vendor: npm
Product: @libp2p/gossipsub
Published: May 21, 2026
Source: GitHub
CVE-2026-46678 MEDIUM - 6.8

Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)

Vendor: pip
Product: pydantic-ai
Published: May 21, 2026
Source: GitHub
CVE-2026-46671 MEDIUM - 4.4

Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory

Vendor: rust
Product: onenote_parser
Published: May 21, 2026
Source: GitHub
CVE-2026-46645 MEDIUM - 4.3

SQLAdmin: Authorization Bypass on `ajax_lookup`

Vendor: pip
Product: sqladmin
Published: May 21, 2026
Source: GitHub

Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: Sandbox property and method bypass via object-destructuring assignment

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

Vendor: composer
Product: twig/markdown-extra
Published: May 21, 2026
Source: GitHub

Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: PHP code injection via `{% use %}` template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments

Vendor: composer
Product: twig/intl-extra
Published: May 21, 2026
Source: GitHub

Twig: The `spaceless` filter implicitly marks its output as safe

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub
CVE-2026-46625 HIGH - 7.5

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

Vendor: npm
Product: js-cookie
Published: May 21, 2026
Source: GitHub
CVE-2026-8428 HIGH - 8.8

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->token->validate('do_update&#...

Vendor: concretecms
Product: concrete_cms
Published: May 21, 2026
Source: NVD