Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,531
Quick preset (or use dates below)
Clear Filters
Showing 2,481 - 2,500 of 13,446 CVEs
CVE-2026-27331 MEDIUM - 6.3

Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.

Vendor: Magepeople inc.
Product: WpTravelly
Published: May 26, 2026
Source: NVD
CVE-2026-25444 MEDIUM - 4.3

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.

Vendor: Magepeople inc.
Product: WpBookingly
Published: May 26, 2026
Source: NVD
CVE-2026-25426 MEDIUM - 5.3

Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.

Vendor: Magepeople inc.
Product: Taxi Booking Manager for WooCommerce
Published: May 26, 2026
Source: NVD
CVE-2026-24520 MEDIUM - 4.3

Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24.

Vendor: bPlugins
Product: Tiktok Feed
Published: May 26, 2026
Source: NVD
CVE-2025-68709 MEDIUM - 5.2

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege esc...

Published: May 26, 2026
Source: NVD

XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin

Vendor: maven
Product: org.xwiki.platform:xwiki-platform-webjars-api
Published: May 26, 2026
Source: GitHub
CVE-2026-9568 MEDIUM - 5.0

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack remotely. The attack...

Published: May 26, 2026
Source: NVD
CVE-2026-9566 MEDIUM - 4.3

A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the component Sign-up. The manipulation of the argument redirect leads to cross site scripting. The attack is possible to be carried ou...

Published: May 26, 2026
Source: NVD
CVE-2026-7453 MEDIUM - 5.3

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7450 MEDIUM - 5.3

A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-48696 MEDIUM - 6.2

FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-44749 MEDIUM - 4.3

The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.

Vendor: SAP_SE
Product: SAP Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-44707 MEDIUM - 6.8

Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker could pre-register an email address they did ...

Vendor: chatwoot
Product: chatwoot
Published: May 26, 2026
Source: NVD
CVE-2026-24201 MEDIUM - 5.8

NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering, denial of service, or information disclosure.

Vendor: NVIDIA
Product: Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24199 MEDIUM - 4.7

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24198 MEDIUM - 5.6

NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive information to an unauthorized actor. A successful exploit of this vulnerability might lead to denial of servi...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla
Published: May 26, 2026
Source: NVD
CVE-2026-24197 MEDIUM - 6.5

NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnera...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24182 MEDIUM - 6.5

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver, Virtual GPU Manager, NVIDIA RTX, Quadro, NVS
Published: May 26, 2026
Source: NVD
CVE-2025-33221 MEDIUM - 4.4

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver
Published: May 26, 2026
Source: NVD
CVE-2026-9565 MEDIUM - 6.3

A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handler. Executing a manipulation can lead to os command injection. The attack can be executed remotely. Th...

Published: May 26, 2026
Source: NVD