Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
Showing 2,641 - 2,660 of 12,982 CVEs

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from the git tree, controllable by an attacker via a malicious branch) into the merge driver command vi...

Vendor: pip
Product: dulwich
Published: May 28, 2026
Source: GitHub
CVE-2026-42305 HIGH - 8.8

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator acce...

Vendor: pip
Product: dulwich
Published: May 28, 2026
Source: GitHub
CVE-2026-48116 HIGH - 7.5

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-controlled pattern parameter to ripgrep as a positional argument without a -- end-of-options separator. ...

Vendor: Mintplex-Labs
Product: anything-llm
Published: May 28, 2026
Source: NVD
CVE-2026-45344 HIGH - 8.1

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fields and writes them back into .env without escaping. A remote attacker who can reach the setup endpoi...

Vendor: Kovah
Product: LinkAce
Published: May 28, 2026
Source: NVD
CVE-2026-39929 HIGH - 7.5

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed pac...

Vendor: Lakeside Software, LLC.
Product: SysTrack Agent
Published: May 28, 2026
Source: NVD
CVE-2026-10044 HIGH - 7.5

Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequence...

Vendor: Usagi-org
Product: ai-goofish-monitor
Published: May 28, 2026
Source: NVD
CVE-2026-46837 HIGH - 8.8

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Suc...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46835 HIGH - 7.5

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result...

Vendor: oracle
Product: database_server
Published: May 28, 2026
Source: NVD
CVE-2026-46834 HIGH - 7.5

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result...

Vendor: oracle
Product: database_server
Published: May 28, 2026
Source: NVD
CVE-2026-46829 HIGH - 7.5

Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-46828 HIGH - 8.1

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful at...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46827 HIGH - 8.8

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful a...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46826 HIGH - 8.8

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Payroll. Successful a...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-46823 HIGH - 7.7

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...

Vendor: oracle
Product: public_sector_financials
Published: May 28, 2026
Source: NVD
CVE-2026-46821 HIGH - 7.7

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financi...

Vendor: oracle
Product: financials_common_modules
Published: May 28, 2026
Source: NVD
CVE-2026-46820 HIGH - 8.5

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financi...

Vendor: oracle
Product: financials_common_modules
Published: May 28, 2026
Source: NVD
CVE-2026-46818 HIGH - 7.4

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successfu...

Vendor: oracle
Product: e-business_suite
Published: May 28, 2026
Source: NVD
CVE-2026-42398 HIGH - 7.7

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations th...

Vendor: Elastic
Product: Kibana
Published: May 28, 2026
Source: NVD
CVE-2026-35277 HIGH - 8.1

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks of this vulnerability can ...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD
CVE-2026-35266 HIGH - 7.9

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. Successful attacks require human interactio...

Vendor: oracle
Product: rest_data_services
Published: May 28, 2026
Source: NVD