Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,526
Quick preset (or use dates below)
Clear Filters
Showing 2,521 - 2,540 of 13,446 CVEs
CVE-2026-48685 MEDIUM - 6.5

FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_bgp_attribute() function correctly identifies when extended_length_bit is set and sets length_of_leng...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48684 MEDIUM - 6.5

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.cpp), the scope parsing loop (lines 224-229) iterates until scopes_offset reaches the attacker-contro...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48683 MEDIUM - 6.5

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check agai...

Published: May 26, 2026
Source: NVD
CVE-2026-46620 MEDIUM - 6.5

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how session_handler::check() handles CSRF tokens. Instead of requiring a token on every state-changing request, it only validat...

Vendor: e107inc
Product: e107
Published: May 26, 2026
Source: NVD
CVE-2026-43936 MEDIUM - 4.3

e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "Media Manager" on the administrator screen. This vulnerability is fixed ...

Vendor: e107inc
Product: e107
Published: May 26, 2026
Source: NVD
CVE-2026-43934 MEDIUM - 6.5

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by others. This stems from inadequate server-side access control validation, where the application depends o...

Vendor: e107inc
Product: e107
Published: May 26, 2026
Source: NVD
CVE-2026-40564 MEDIUM - 6.5

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a user with CR create permissions read file...

Vendor: Apache Software Foundation
Product: Apache Flink Kubernetes Operator
Published: May 26, 2026
Source: NVD
CVE-2026-38587 MEDIUM - 4.3

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique i...

Published: May 26, 2026
Source: NVD
CVE-2026-41917 MEDIUM - 4.9

OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with action=Load. Attackers can ...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD
CVE-2026-41401 MEDIUM - 6.5

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadat...

Vendor: libyang
Product: libyang
Published: May 26, 2026
Source: NVD
CVE-2026-9542 MEDIUM - 6.3

A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available...

Published: May 26, 2026
Source: NVD
CVE-2026-9541 MEDIUM - 5.3

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been re...

Vendor: squirrel-lang
Product: squirrel
Published: May 26, 2026
Source: NVD
CVE-2026-9540 MEDIUM - 5.3

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The...

Published: May 26, 2026
Source: NVD
CVE-2026-8174 MEDIUM - 5.7

Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.

Published: May 26, 2026
Source: NVD
CVE-2026-48136 MEDIUM - 4.1

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions...

Vendor: checkpoint
Product: Quantum Security Management
Published: May 26, 2026
Source: NVD
CVE-2026-48135 MEDIUM - 5.3

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-39642 MEDIUM - 5.3

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.

Vendor: SpabRice
Product: Nyla
Published: May 26, 2026
Source: NVD
CVE-2026-27427 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.

Vendor: Dylan Kuhn
Product: Geo Mashup
Published: May 26, 2026
Source: NVD
CVE-2026-24638 MEDIUM - 4.3

Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

Vendor: Webful Creations
Product: RepairBuddy
Published: May 26, 2026
Source: NVD
CVE-2026-24590 MEDIUM - 5.3

Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.

Vendor: VideoWhisper.com
Product: Paid Videochat Turnkey Site
Published: May 26, 2026
Source: NVD