Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,531
Quick preset (or use dates below)
Clear Filters
Showing 2,461 - 2,480 of 13,446 CVEs
CVE-2026-42568 MEDIUM - 4.3

Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13....

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 26, 2026
Source: GitHub
CVE-2026-9604 MEDIUM - 4.3

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. U...

Published: May 26, 2026
Source: NVD
CVE-2026-8647 MEDIUM - 4.8

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::...

Published: May 26, 2026
Source: NVD
CVE-2026-46740 MEDIUM - 5.3

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd...

Vendor: RRWO
Product: Mojolicious::Plugin::Statsd
Published: May 26, 2026
Source: NVD
CVE-2026-41207 MEDIUM - 5.3

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distinguish success from failure. Since this output is used as HKDF key material for the response AEAD, a ...

Vendor: maven
Product: io.netty.incubator:netty-incubator-codec-ohttp
Published: May 26, 2026
Source: GitHub
CVE-2026-9603 MEDIUM - 6.5

A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been...

Published: May 26, 2026
Source: NVD
CVE-2026-48710 MEDIUM - 6.5

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed hea...

Vendor: Kludex
Product: starlette
Published: May 26, 2026
Source: NVD
CVE-2026-42015 MEDIUM - 5.3

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of s...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 26, 2026
Source: NVD
CVE-2025-46307 MEDIUM - 5.5

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-46280 MEDIUM - 5.5

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43451 MEDIUM - 5.5

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43290 MEDIUM - 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to modify protected parts of the file system.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43289 MEDIUM - 5.5

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2026-9583 MEDIUM - 4.3

A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be per...

Published: May 26, 2026
Source: NVD
CVE-2026-9582 MEDIUM - 4.3

A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to ...

Published: May 26, 2026
Source: NVD
CVE-2026-9581 MEDIUM - 6.3

A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 3.9.2...

Published: May 26, 2026
Source: NVD
CVE-2026-9579 MEDIUM - 6.3

A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. The attack may be launched remotely. The exploit has...

Published: May 26, 2026
Source: NVD
CVE-2026-47672 MEDIUM - 6.5

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g....

Vendor: oviva-ag
Product: epa4all-client
Published: May 26, 2026
Source: NVD
CVE-2026-44443 MEDIUM - 4.8

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's auth.api.signUpEmail() ca...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-36239 MEDIUM - 4.3

PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

Published: May 26, 2026
Source: NVD