Total CVEs

133,035

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,068
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,501 - 2,520 of 29,440 CVEs
CVE-2026-44049 HIGH - 7.5

An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character data.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-44048 HIGH - 8.8

A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-44047 HIGH - 8.8

An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-6279 CRITICAL - 9.8

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-...

Published: May 21, 2026
Source: NVD
CVE-2026-2734 MEDIUM - 6.5

In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all register...

Published: May 21, 2026
Source: NVD
CVE-2026-1543 MEDIUM - 6.4

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all versions up to, and including, 3.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level acce...

Published: May 21, 2026
Source: NVD
CVE-2026-4811 MEDIUM - 4.9

The WPB Floating Menu & Categories for WordPress โ€“ Sticky Side Menu with Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Icon CSS Class' category field in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escapin...

Published: May 21, 2026
Source: NVD

A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tokens, or any form of identity verification. An unauthenticated network attacker who can reference a target workspace'...

Published: May 21, 2026
Source: NVD
CVE-2026-48172 CRITICAL - 9.8

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. LiteSpeed WHM Plugin (the parent plugin) is unaffected. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs...

Vendor: LiteSpeed Technologies
Product: cPanel Plugin
Published: May 21, 2026
Source: NVD
CVE-2026-1881 MEDIUM - 4.3

The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.52.2 via the get_sponsored_meta AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level acc...

Published: May 21, 2026
Source: NVD
CVE-2026-9149 MEDIUM - 6.5

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could ...

Published: May 21, 2026
Source: NVD
CVE-2026-40165 HIGH - 8.7

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an at...

Vendor: goauthentik
Product: authentik
Published: May 21, 2026
Source: NVD
CVE-2026-9150 MEDIUM - 6.5

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption...

Published: May 20, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: May 20, 2026
Source: NVD

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmat...

Vendor: Siber Systems, Inc.
Product: Android App "RoboForm Password Manager"
Published: May 20, 2026
Source: NVD
CVE-2026-47372 CRITICAL - 9.1

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

Vendor: RRWO
Product: Crypt::SaltedHash
Published: May 20, 2026
Source: NVD
CVE-2026-40102 MEDIUM - 6.5

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field R...

Vendor: makeplane
Product: plane
Published: May 20, 2026
Source: NVD
CVE-2026-40094 MEDIUM - 4.3

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and stores them in a peer contact book, eventually leading to address book crash. A PeerContact can l...

Vendor: nimiq
Product: core-rs-albatross
Published: May 20, 2026
Source: NVD
CVE-2026-8632 HIGH - 7.8

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.

Vendor: hp
Product: linux_imaging_and_printing
Published: May 20, 2026
Source: NVD
CVE-2026-8631 CRITICAL - 9.8

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.

Vendor: hp
Product: linux_imaging_and_printing
Published: May 20, 2026
Source: NVD