Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,526
Quick preset (or use dates below)
Clear Filters
Showing 2,501 - 2,520 of 13,446 CVEs
CVE-2026-8852 MEDIUM - 6.2

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-48905 MEDIUM - 6.1

Lack of input filtering leads to an XSS vector in the HTML filter code.

Vendor: Joomla! Project
Product: Joomla! Framework Filter package
Published: May 26, 2026
Source: NVD
CVE-2026-48903 MEDIUM - 6.1

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

Vendor: Joomla! Project
Product: Joomla! Framework Filter package
Published: May 26, 2026
Source: NVD
CVE-2026-48900 MEDIUM - 4.3

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48693 MEDIUM - 5.5

FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The print_screen_contents_into_file() function (src/fastnetmon_logic.cpp line 218...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-47728 MEDIUM - 4.3

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one project could cause event processing in that project to use sour...

Vendor: bugsink
Product: bugsink
Published: May 26, 2026
Source: NVD
CVE-2026-44723 MEDIUM - 5.0

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_g...

Vendor: VowpalWabbit
Product: vowpal_wabbit
Published: May 26, 2026
Source: NVD
CVE-2026-44314 MEDIUM - 4.3

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic ...

Vendor: traccar
Product: traccar
Published: May 26, 2026
Source: NVD
CVE-2026-35220 MEDIUM - 4.3

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30895 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30894 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the content history component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-25901 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-25900 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the feed modules.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2025-36221 MEDIUM - 5.3

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

Vendor: IBM
Product: Cloud Pak for Data System - Cyclops
Published: May 26, 2026
Source: NVD
CVE-2025-36220 MEDIUM - 4.3

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Vendor: IBM
Product: Cloud Pak for Data System - Cyclops
Published: May 26, 2026
Source: NVD
CVE-2025-36148 MEDIUM - 5.4

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the int...

Vendor: IBM
Product: Financial Transaction Manager for SWIFT Services for Multiplatforms
Published: May 26, 2026
Source: NVD
CVE-2025-36145 MEDIUM - 5.4

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.

Vendor: IBM
Product: watsonx.data
Published: May 26, 2026
Source: NVD
CVE-2025-36126 MEDIUM - 6.4

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functi...

Vendor: IBM
Product: Cognos Analytics, Cognos Transformer
Published: May 26, 2026
Source: NVD
CVE-2025-14290 MEDIUM - 5.4

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially lea...

Vendor: IBM
Product: webMethods Integration (on prem) -Integration Server
Published: May 26, 2026
Source: NVD
CVE-2025-13755 MEDIUM - 5.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.

Vendor: IBM
Product: Db2
Published: May 26, 2026
Source: NVD