Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,381 - 2,400 of 12,388 CVEs
CVE-2026-46345 HIGH - 8.4

compliance-trestle - jinja has an Arbitrary File Write via Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-9096 HIGH - 7.5

Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are com...

Published: May 28, 2026
Source: NVD
CVE-2026-9095 HIGH - 8.1

Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcem...

Published: May 28, 2026
Source: NVD
CVE-2026-8697 HIGH - 8.8

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitati...

Vendor: tp-link
Product: archer_c64_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-44466 HIGH - 8.6

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like echo. This vulnerability is fixed in 0.229.0.

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-44465 HIGH - 8.6

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration option. This allows an attacker to achieve Remote Code Execution (RCE) when a victim open a folder in untrusted mode. T...

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-44463 HIGH - 8.6

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-44461 HIGH - 8.6

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or validation. If an attacker can control an environment variable key (for example via project terminal...

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-48526 HIGH - 7.4

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret...

Vendor: jpadilla
Product: pyjwt
Published: May 28, 2026
Source: NVD
CVE-2026-47762 HIGH - 8.7

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This v...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-47761 HIGH - 8.7

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugi...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-47760 HIGH - 8.7

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerabili...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-47759 HIGH - 8.7

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypa...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-44358 HIGH - 8.2

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for bot...

Vendor: espressif
Product: shared-github-dangerjs
Published: May 28, 2026
Source: NVD
CVE-2026-41565 HIGH - 7.5

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer...

Vendor: MIK
Product: CryptX
Published: May 28, 2026
Source: NVD
CVE-2026-35676 HIGH - 8.2

phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending P...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD
CVE-2026-35675 HIGH - 8.2

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via emai...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD
CVE-2026-35672 HIGH - 7.5

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers can send an empty x-pmf-token header to bypass token validation and inject malicious content via POST ...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD
CVE-2026-35671 HIGH - 8.8

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to Su...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD