Total CVEs

131,504

Critical Severity

2,798

High Severity

10,012

Last 7 Days

1,135
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,401 - 2,420 of 27,909 CVEs
CVE-2020-37174 MEDIUM - 5.5

WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design tab textfields. Attackers can inject JavaScript code through fields like 'Text for block toggle&...

Vendor: HUSKY
Product: Products Filter Professional for WooCommerce
Published: May 13, 2026
Source: NVD
CVE-2020-37169 MEDIUM - 5.5

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP fil...

Vendor: Ultimate Member
Product: ultimate-member
Published: May 13, 2026
Source: NVD
CVE-2020-37168 CRITICAL - 9.8

Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, the...

Vendor: Paiement
Product: Ecommerce Systempay
Published: May 13, 2026
Source: NVD
CVE-2026-45375 CRITICAL - 9.0

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings โ†’ Marketplace UI...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/getLocalGraph, POST /api/sync/setSyncInterval, POST /api/storage/updateRecentDocViewTime, POST /api/st...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45083 CRITICAL - 9.8

Goobi viewer - Core: Unauthenticated Solr Streaming Expression Proxy

Vendor: maven
Product: io.goobi.viewer:viewer-core
Published: May 13, 2026
Source: GitHub
CVE-2026-45152 HIGH - 7.8

uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution

Vendor: go
Product: gitlab.com/uniget-org/cli
Published: May 13, 2026
Source: GitHub
CVE-2026-45148 MEDIUM - 4.3

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate metadata from documents that are invisible to the publish service. This vulnerability is fixed in 3....

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45147 MEDIUM - 4.3

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the handler performing a configuration write that is normally guarded by both. Any authenti...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45137 HIGH - 8.2

Anchor: Program<'info, System> is not properly validated

Vendor: rust
Product: anchor-lang
Published: May 13, 2026
Source: GitHub

claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh

Vendor: npm
Product: claude-code-cache-fix
Published: May 13, 2026
Source: GitHub
CVE-2026-44798 HIGH - 7.1

Nautobot: GitRepository.current_head field should not be writable through REST API

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44797 HIGH - 8.5

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44796 MEDIUM - 6.5

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44794 MEDIUM - 5.4

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44774 MEDIUM - 9.9

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider a...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: May 13, 2026
Source: GitHub
CVE-2026-44740 MEDIUM - 6.5

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 13, 2026
Source: GitHub
CVE-2026-45134 HIGH - 7.1

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

Vendor: pip
Product: langsmith
Published: May 13, 2026
Source: GitHub
CVE-2026-44724 HIGH - 7.8

Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name

Vendor: npm
Product: systeminformation
Published: May 13, 2026
Source: GitHub
CVE-2026-8463 MEDIUM - 5.3

Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without checking that encoded_len is non-zero. When the encoded string is ...

Vendor: leont
Product: crypt\
Published: May 13, 2026
Source: NVD