Total CVEs

133,035

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,068
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,561 - 2,580 of 29,440 CVEs
CVE-2026-35008 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into an HTML attribute. Attackers can craft a maliciou...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35007 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id GET parameter directly into an HTML attribute. Attackers can craft a malicious ...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without ...

Vendor: xwiki
Product: xwiki-platform
Published: May 20, 2026
Source: NVD
CVE-2026-2813 MEDIUM - 4.7

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended, untrusted site, resulting ...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD
CVE-2026-2812 MEDIUM - 5.3

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This is...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD
CVE-2026-26028 MEDIUM - 6.1

CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of <iframe>, <video>, and <audio&...

Vendor: cryptpad
Product: cryptpad
Published: May 20, 2026
Source: NVD
CVE-2026-24218 HIGH - 8.1

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attack...

Vendor: NVIDIA
Product: DGX Spark
Published: May 20, 2026
Source: NVD
CVE-2026-24217 HIGH - 8.8

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-24216 HIGH - 7.8

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-24188 HIGH - 8.2

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.

Vendor: NVIDIA
Product: TensorRT
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnera...

Vendor: xwiki
Product: xwiki-commons
Published: May 20, 2026
Source: NVD
CVE-2026-30691 MEDIUM - 6.1

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode

Published: May 20, 2026
Source: NVD
CVE-2026-20240 MEDIUM - 6.5

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the β€˜admin’ or β€˜power’ Splunk roles could cause a Denial of ...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-20239 HIGH - 7.5

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-20238 MEDIUM - 6.5

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configu...

Vendor: Splunk
Product: Splunk AI Toolkit
Published: May 20, 2026
Source: NVD
CVE-2026-9101 MEDIUM - 4.3

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

Published: May 20, 2026
Source: NVD
CVE-2026-9100 MEDIUM - 5.9

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process ...

Published: May 20, 2026
Source: NVD
CVE-2026-9087 MEDIUM - 6.4

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Published: May 20, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 20, 2026
Source: NVD
CVE-2026-7613 HIGH - 7.2

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

Published: May 20, 2026
Source: NVD