Total CVEs

133,033

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,072
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,401 - 2,420 of 29,438 CVEs
CVE-2026-48215 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_id POST parameter directly into an HTML form input value attribute. Attackers can c...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48214 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id POST parameter directly into an HTML form input value attribute and an inline...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-39593 MEDIUM - 6.5

Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HAPPY: from n/a through 1.0.10.

Vendor: VillaTheme
Product: HAPPY
Published: May 21, 2026
Source: NVD
CVE-2026-46492 HIGH - 7.2

md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)

Vendor: npm
Product: md-fileserver
Published: May 21, 2026
Source: GitHub
CVE-2026-46432 HIGH - 7.8

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

Vendor: pip
Product: lmdeploy
Published: May 21, 2026
Source: GitHub
CVE-2026-48213 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id POST parameter directly into an HTML form input value attribute. Attackers can c...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48207 CRITICAL - 9.8

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Pyt...

Vendor: Apache Software Foundation
Product: Apache Fory
Published: May 21, 2026
Source: NVD

samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions

Vendor: npm
Product: samlify
Published: May 21, 2026
Source: GitHub

Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing

Vendor: pip
Product: mvt
Published: May 21, 2026
Source: GitHub
CVE-2026-46403 MEDIUM - 6.3

Klever-Go KVM read-only execution can commit contract delete and upgrade side effects

Vendor: go
Product: github.com/klever-io/klever-go
Published: May 21, 2026
Source: GitHub
CVE-2026-46481 HIGH - 8.3

OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users

Vendor: maven
Product: org.open-metadata:openmetadata-service
Published: May 21, 2026
Source: GitHub
CVE-2026-9089 HIGH - 8.8

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

Vendor: connectwise
Product: automate
Published: May 21, 2026
Source: NVD
CVE-2026-39531 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0.

Vendor: Wp Directory Kit
Product: WP Directory Kit
Published: May 21, 2026
Source: NVD
CVE-2026-36189 MEDIUM - 6.2

Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106fedb4a4f510972bdc allows a local attacker to cause a denial of service via the check_template.cpp, check_template function, tokenize_cleanup function, uncrustif...

Published: May 21, 2026
Source: NVD
CVE-2026-1816 MEDIUM - 6.3

Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13.

Published: May 21, 2026
Source: NVD
CVE-2026-1815 MEDIUM - 5.7

Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 before 1.13.

Published: May 21, 2026
Source: NVD
CVE-2026-45208 HIGH - 7.8

A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-45207 HIGH - 7.8

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45206 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability ...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-45206 HIGH - 7.8

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability ...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-34930 HIGH - 7.8

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different process protection mechanism. Please note: an attacker must first obtain the ability to execute low...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD