Total CVEs

132,167

Critical Severity

2,835

High Severity

10,137

Last 7 Days

1,642
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,421 - 2,440 of 28,572 CVEs
CVE-2026-8695 HIGH - 7.5

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debu...

Vendor: radare
Product: radare2
Published: May 15, 2026
Source: NVD
CVE-2026-46383 MEDIUM - 5.5

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm instal...

Vendor: microsoft
Product: apm
Published: May 15, 2026
Source: NVD
CVE-2026-45539 HIGH - 7.4

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rglob() calls and read each match with Path.read_text(), transparently following symbolic links. A symli...

Vendor: microsoft
Product: apm
Published: May 15, 2026
Source: NVD
CVE-2026-45038 HIGH - 7.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45037 HIGH - 7.1

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafte...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45036 HIGH - 7.0

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatically confirms ZMODEM protocol detection on all terminal session output without user interaction, enabling shell command execution when a user displays attacker-controlled content. Th...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45035 HIGH - 8.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or san...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-44717 CRITICAL - 9.8

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.

Vendor: 611711Dark
Product: mcp_calculate_server
Published: May 15, 2026
Source: NVD

LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes HMAC verification to run with a zero-length key, so an attacker can forge a valid JW...

Vendor: benmcollins
Product: libjwt
Published: May 15, 2026
Source: NVD
CVE-2026-23695 MEDIUM - 5.4

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html direct...

Vendor: Cockpit-HQ
Product: Cockpit
Published: May 15, 2026
Source: NVD
CVE-2026-45106 MEDIUM - 4.6

Weblate: Stored HTML injection in editor search preview

Vendor: pip
Product: weblate
Published: May 15, 2026
Source: GitHub
CVE-2026-45062 HIGH - 8.1

FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files

Vendor: go
Product: github.com/dunglas/frankenphp
Published: May 15, 2026
Source: GitHub
CVE-2026-44716 HIGH - 7.5

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint β€” Arbitrary File Read via `%2F`-Encoded Separator

Vendor: pip
Product: pipecat-ai
Published: May 15, 2026
Source: GitHub
CVE-2026-41147 HIGH - 8.7

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies primarily on client-side filtering to sanitize HTML tags and attri...

Vendor: composer
Product: nukeviet/nukeviet
Published: May 15, 2026
Source: GitHub
CVE-2026-40092 HIGH - 7.5

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, Ke...

Vendor: rust
Product: nimiq-keys
Published: May 15, 2026
Source: GitHub
CVE-2026-22810 HIGH - 8.2

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded fil...

Vendor: npm
Product: @joplin/onenote-converter
Published: May 15, 2026
Source: GitHub
CVE-2025-65954 MEDIUM - 4.7

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the br...

Vendor: composer
Product: simplesamlphp/simplesamlphp-module-casserver
Published: May 15, 2026
Source: GitHub
CVE-2026-46508 HIGH - 7.8

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and tas...

Vendor: vercel
Product: turborepo
Published: May 15, 2026
Source: NVD

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed. The vulnerability...

Vendor: cli
Product: cli
Published: May 15, 2026
Source: NVD
CVE-2026-45773 MEDIUM - 6.5

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send...

Vendor: vercel
Product: turborepo
Published: May 15, 2026
Source: NVD