Total CVEs

131,518

Critical Severity

2,798

High Severity

10,013

Last 7 Days

1,134
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,641 - 2,660 of 27,923 CVEs
CVE-2026-23823 HIGH - 7.2

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only im...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23822 MEDIUM - 5.3

A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption o...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23821 HIGH - 7.2

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operati...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23820 HIGH - 7.2

A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying o...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23819 HIGH - 8.8

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to com...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-5146 MEDIUM - 4.3

Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 throu...

Published: May 12, 2026
Source: NVD
CVE-2026-44343 CRITICAL - 9.8

WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. This vulnerability is fixed in 4.3.2.

Vendor: WGDashboard
Product: WGDashboard
Published: May 12, 2026
Source: NVD
CVE-2026-44279 MEDIUM - 5.5

A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to improper access control via <insert attack vector here>

Vendor: Fortinet
Product: FortiTokenAndroid
Published: May 12, 2026
Source: NVD

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

Vendor: Fortinet
Product: FortiClientWindows
Published: May 12, 2026
Source: NVD
CVE-2026-44277 CRITICAL - 9.8

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Vendor: Fortinet
Product: FortiAuthenticator
Published: May 12, 2026
Source: NVD
CVE-2026-44204 MEDIUM - 6.5

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role) to execute arbitrary SQL and read data from any table in the database, including data belonging to o...

Vendor: Shelf-nu
Product: shelf.nu
Published: May 12, 2026
Source: NVD
CVE-2026-44196 CRITICAL - 9.1

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker ...

Vendor: smp46
Product: pingvin-share-x
Published: May 12, 2026
Source: NVD
CVE-2026-44184 HIGH - 8.0

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddre...

Vendor: Cleanuparr
Product: Cleanuparr
Published: May 12, 2026
Source: NVD
CVE-2026-44183 CRITICAL - 9.8

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the client IP. That entry ...

Vendor: Cleanuparr
Product: Cleanuparr
Published: May 12, 2026
Source: NVD
CVE-2026-43892 HIGH - 8.8

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16.

Vendor: AntSwordProject
Product: antSword
Published: May 12, 2026
Source: NVD
CVE-2026-42899 HIGH - 7.5

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Vendor: microsoft
Product: .net
Published: May 12, 2026
Source: NVD
CVE-2026-42898 CRITICAL - 9.9

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: dynamics_365
Published: May 12, 2026
Source: NVD
CVE-2026-42896 HIGH - 7.8

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_11_24h2
Published: May 12, 2026
Source: NVD
CVE-2026-42893 HIGH - 7.4

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: outlook
Published: May 12, 2026
Source: NVD
CVE-2026-42891 MEDIUM - 6.5

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 12, 2026
Source: NVD