Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
Showing 2,541 - 2,560 of 13,461 CVEs
CVE-2026-43934 MEDIUM - 6.5

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by others. This stems from inadequate server-side access control validation, where the application depends o...

Vendor: e107inc
Product: e107
Published: May 26, 2026
Source: NVD
CVE-2026-40564 MEDIUM - 6.5

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses.  This lets a user with CR create permissions read file...

Vendor: Apache Software Foundation
Product: Apache Flink Kubernetes Operator
Published: May 26, 2026
Source: NVD
CVE-2026-38587 MEDIUM - 4.3

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique i...

Published: May 26, 2026
Source: NVD
CVE-2026-41917 MEDIUM - 4.9

OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with action=Load. Attackers can ...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD
CVE-2026-41401 MEDIUM - 6.5

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadat...

Vendor: libyang
Product: libyang
Published: May 26, 2026
Source: NVD
CVE-2026-9542 MEDIUM - 6.3

A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available...

Published: May 26, 2026
Source: NVD
CVE-2026-9541 MEDIUM - 5.3

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been re...

Vendor: squirrel-lang
Product: squirrel
Published: May 26, 2026
Source: NVD
CVE-2026-9540 MEDIUM - 5.3

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The...

Published: May 26, 2026
Source: NVD
CVE-2026-8174 MEDIUM - 5.7

Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.

Published: May 26, 2026
Source: NVD
CVE-2026-48136 MEDIUM - 4.1

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions...

Vendor: checkpoint
Product: Quantum Security Management
Published: May 26, 2026
Source: NVD
CVE-2026-48135 MEDIUM - 5.3

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-39642 MEDIUM - 5.3

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.

Vendor: SpabRice
Product: Nyla
Published: May 26, 2026
Source: NVD
CVE-2026-27427 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.

Vendor: Dylan Kuhn
Product: Geo Mashup
Published: May 26, 2026
Source: NVD
CVE-2026-24638 MEDIUM - 4.3

Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

Vendor: Webful Creations
Product: RepairBuddy
Published: May 26, 2026
Source: NVD
CVE-2026-24590 MEDIUM - 5.3

Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.

Vendor: VideoWhisper.com
Product: Paid Videochat Turnkey Site
Published: May 26, 2026
Source: NVD
CVE-2026-39655 MEDIUM - 5.3

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

Vendor: TeconceTheme
Product: Mayosis Core
Published: May 26, 2026
Source: NVD
CVE-2026-9534 MEDIUM - 6.3

A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit...

Published: May 26, 2026
Source: NVD
CVE-2026-9533 MEDIUM - 6.3

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate th...

Published: May 26, 2026
Source: NVD
CVE-2026-9532 MEDIUM - 6.3

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed f...

Published: May 26, 2026
Source: NVD
CVE-2026-3314 MEDIUM - 4.6

Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This is...

Published: May 26, 2026
Source: NVD