Total CVEs

133,033

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,072
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,341 - 2,360 of 29,438 CVEs
CVE-2026-46552 MEDIUM - 5.8

NocoDB: Shared-base link access can invite arbitrary users as persistent base members

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46551 MEDIUM - 6.5

NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46550 MEDIUM - 5.4

NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub

NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46548 MEDIUM - 4.3

NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46547 MEDIUM - 6.1

NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46519 HIGH - 8.8

MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement

Vendor: npm
Product: mcp-server-kubernetes
Published: May 21, 2026
Source: GitHub

SpiceDB: Caveat structures with nested lists can result in improper cache reuse

Vendor: go
Product: github.com/authzed/spicedb
Published: May 21, 2026
Source: GitHub

Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss

Vendor: rust
Product: p3-challenger
Published: May 21, 2026
Source: GitHub

Snappy: Binary path is never shell-escaped due to an inverted is_executable check

Vendor: composer
Product: KnpLabs/knp-snappy
Published: May 21, 2026
Source: GitHub

Snappy : SSRF and local file read via the xsl-style-sheet option

Vendor: composer
Product: knplabs/knp-snappy
Published: May 21, 2026
Source: GitHub

Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-4843 MEDIUM - 4.3

The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access an...

Published: May 21, 2026
Source: NVD
CVE-2026-47114 HIGH - 8.8

IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes...

Vendor: iina
Product: iina
Published: May 21, 2026
Source: NVD

Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46614 CRITICAL - 9.8

Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46612 HIGH - 8.8

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46616 MEDIUM - 5.4

Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

Vendor: nuget
Product: Umbraco.Cms
Published: May 21, 2026
Source: GitHub
CVE-2026-46561 MEDIUM - 5.0

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with...

Vendor: pip
Product: pyload-ng
Published: May 21, 2026
Source: GitHub
CVE-2026-46545 HIGH - 7.5

nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item

Vendor: rust
Product: nimiq-primitives
Published: May 21, 2026
Source: GitHub