Total CVEs

133,035

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,071
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,541 - 2,560 of 29,440 CVEs
CVE-2026-9113 MEDIUM - 4.3

Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9112 HIGH - 8.8

Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9111 HIGH - 8.8

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9110 MEDIUM - 4.2

Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD

A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated workspace user can supply a crafted filename in the multipart Content-Disposition header to escape the intended tempora...

Published: May 20, 2026
Source: NVD
CVE-2026-9082 MEDIUM - 6.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from...

Vendor: drupal
Product: drupal
Published: May 20, 2026
Source: NVD
CVE-2026-47099 MEDIUM - 6.1

TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted JSON payload containing a malicious _constructor-name_ property value. The custom reviver passes the constructor name ...

Vendor: storybookjs
Product: telejson
Published: May 20, 2026
Source: NVD
CVE-2026-45444 CRITICAL - 10.0

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

Vendor: WP Swings
Product: Gift Cards For WooCommerce Pro
Published: May 20, 2026
Source: NVD

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.

Vendor: frappe
Product: lms
Published: May 20, 2026
Source: NVD

Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.

Vendor: frappe
Product: frappe
Published: May 20, 2026
Source: NVD
CVE-2026-39311 MEDIUM - 6.8

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw where lack of SVG sanitization combined with a disabled Content Security Policy (CSP) and a publicly reachable backe...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-39310 HIGH - 8.6

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an ...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-35016 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_query POST parameter directly into an HTML input field VALUE attribute. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35015 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the the_ticket GET parameter directly into a JavaScript variable assignment. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35014 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35013 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values through the thelat and thelng GET parameters directly into JavaScript variable assignments. Atta...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35012 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attack...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35011 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_call GET parameter directly into page output. Attackers can craft a malicious URL co...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35010 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a JavaScript variable assignment. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35009 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD