Total CVEs

131,504

Critical Severity

2,798

High Severity

10,012

Last 7 Days

1,124
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,581 - 2,600 of 27,909 CVEs

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the root inode (inode 2) is set to IFLNK (symlink) instead of IFDI...

Vendor: M2Team
Product: NanaZip
Published: May 12, 2026
Source: NVD

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's Ge...

Vendor: M2Team
Product: NanaZip
Published: May 12, 2026
Source: NVD
CVE-2026-34690 HIGH - 7.8

After Effects versions 26.0, 25.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: After Effects
Published: May 12, 2026
Source: NVD
CVE-2026-34688 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation o...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34686 HIGH - 8.7

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may b...

Vendor: Adobe
Product: Adobe Commerce
Published: May 12, 2026
Source: NVD

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier [NEEDS REVIEW: impact mismatch โ€” ticket says 'Arbitrary file system write', CIA triad derives 'Security Feature Bypass'. Verify CVSS vector before publishing.] are affected by an ...

Vendor: Adobe
Product: Adobe Commerce
Published: May 12, 2026
Source: NVD
CVE-2026-34680 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitat...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34679 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation o...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34678 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service cond...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34677 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service cond...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34673 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service cond...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34672 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. E...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34671 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitat...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34670 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation o...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34669 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation o...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34668 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation o...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34667 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. E...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34666 MEDIUM - 6.2

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation o...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34665 HIGH - 7.5

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service cond...

Vendor: Adobe
Product: CAI Content Credentials
Published: May 12, 2026
Source: NVD
CVE-2026-34658 MEDIUM - 4.8

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may ...

Vendor: Adobe
Product: Adobe Commerce
Published: May 12, 2026
Source: NVD