Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,361 - 2,380 of 12,388 CVEs
CVE-2026-46827 HIGH - 8.8

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful a...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46826 HIGH - 8.8

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Payroll. Successful a...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46823 HIGH - 7.7

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...

Vendor: oracle
Product: public_sector_financials
Published: May 28, 2026
Source: NVD
CVE-2026-46821 HIGH - 7.7

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financi...

Vendor: oracle
Product: financials_common_modules
Published: May 28, 2026
Source: NVD
CVE-2026-46820 HIGH - 8.5

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financi...

Vendor: oracle
Product: financials_common_modules
Published: May 28, 2026
Source: NVD
CVE-2026-46818 HIGH - 7.4

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successfu...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-42398 HIGH - 7.7

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations th...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-35277 HIGH - 8.1

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can ...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-35266 HIGH - 7.9

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks require human interactio...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-49128 HIGH - 7.5

Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root with a user-supplied URI as plain strings without canoni...

Vendor: MusicPlayerDaemon
Product: MPD
Published: May 28, 2026
Source: NVD
CVE-2026-49127 HIGH - 8.6

Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD c...

Vendor: MusicPlayerDaemon
Product: MPD
Published: May 28, 2026
Source: NVD
CVE-2026-32847 HIGH - 7.5

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette&...

Vendor: HKUDS
Product: DeepCode
Published: May 28, 2026
Source: NVD
CVE-2026-4944 HIGH - 8.8

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This bypasses the user's explicit `--trust-remote-cod...

Published: May 28, 2026
Source: NVD
CVE-2026-47333 HIGH - 7.8

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data bei...

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-47331 HIGH - 7.8

Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD
CVE-2026-30761 HIGH - 7.3

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

Published: May 28, 2026
Source: NVD
CVE-2026-30760 HIGH - 7.3

An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

Published: May 28, 2026
Source: NVD
CVE-2026-46439 HIGH - 7.8

compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-45296 HIGH - 7.7

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API key itself is valid and that the target projectKey exists. The authorization flow does not veri...

Vendor: openreplay
Product: openreplay
Published: May 28, 2026
Source: NVD
CVE-2026-34126 HIGH - 7.5

TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range...

Vendor: TP-Link Systems Inc., TP Link Systems Inc.
Product: Tapo L535E v1.0, v3.0, Tapo P300 v1.0, Tapo D100C v1.0
Published: May 28, 2026
Source: NVD