Total CVEs

133,035

Critical Severity

2,915

High Severity

10,571

Last 7 Days

2,068
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,621 - 2,640 of 29,440 CVEs
CVE-2026-3593 HIGH - 7.4

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-3592 MEDIUM - 5.3

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 throu...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-3039 HIGH - 7.5

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-sec...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-29518 HIGH - 7.0

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-27424 MEDIUM - 4.3

Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.

Vendor: WP Chill
Product: Image Photo Gallery Final Tiles Grid
Published: May 20, 2026
Source: NVD
CVE-2026-27405 MEDIUM - 6.5

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.

Vendor: Magepeople inc.
Product: WpBookingly
Published: May 20, 2026
Source: NVD
CVE-2026-24573 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0.

Vendor: Themeisle
Product: Visualizer
Published: May 20, 2026
Source: NVD
CVE-2025-11954 HIGH - 8.0

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Vendor: Sitemio Information Technologies Trade Ltd. Co.
Product: WISECP
Published: May 20, 2026
Source: NVD

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.

Vendor: HCL
Product: BigFix Service Management (SM)
Published: May 20, 2026
Source: NVD
CVE-2025-31973 MEDIUM - 4.0

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

Vendor: HCL
Product: BigFix Service Management (SM)
Published: May 20, 2026
Source: NVD
CVE-2026-25602 MEDIUM - 4.4

Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: th...

Vendor: Mesalvo
Product: Meona Client Launcher Component, Meona Server Component
Published: May 20, 2026
Source: NVD
CVE-2026-22315 HIGH - 7.2

Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export  of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server C...

Vendor: Mesalvo
Product: Meona Client Launcher Component, Meona Server Component
Published: May 20, 2026
Source: NVD
CVE-2026-22314 CRITICAL - 9.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Ser...

Vendor: Mesalvo
Product: Meona Client Launcher Component, Meona Server Component
Published: May 20, 2026
Source: NVD
CVE-2026-0857 MEDIUM - 6.0

Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

Published: May 20, 2026
Source: NVD
CVE-2026-0856 HIGH - 7.8

Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

Published: May 20, 2026
Source: NVD
CVE-2026-9064 HIGH - 7.5

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal control...

Published: May 20, 2026
Source: NVD
CVE-2026-6728 MEDIUM - 5.3

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected pos...

Published: May 20, 2026
Source: NVD
CVE-2026-44933 HIGH - 7.8

`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root priv...

Vendor: SUSE
Product: SUSE Linux Enterprise, openSUSE
Published: May 20, 2026
Source: NVD
CVE-2026-44608 MEDIUM - 5.9

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash....

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-44390 MEDIUM - 5.3

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound ...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD