Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,698
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,681 - 2,700 of 13,146 CVEs
CVE-2026-47070 MEDIUM - 6.1

Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl passes the original request headers unchanged to the redirect target without performing any cross-origin check. When a client issues an HTTP/3 request w...

Vendor: benoitc
Product: hackney
Published: May 25, 2026
Source: NVD
CVE-2026-47069 MEDIUM - 5.3

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:setcookie/3 function in src/hackney_cookie.erl validates the Name and Value arguments against CRLF and control characters, but concatenates the d...

Vendor: benoitc
Product: hackney
Published: May 25, 2026
Source: NVD
CVE-2018-25378 MEDIUM - 6.2

Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can create a malicious text file containing 500 or more characters, paste the content into the New Notebook N...

Vendor: Stokedonit
Product: Notebook Pro
Published: May 25, 2026
Source: NVD
CVE-2018-25370 MEDIUM - 5.3

Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with parameters like rol_assign_roles, rol_approve_users, and ...

Vendor: Admidio
Product: Admidio
Published: May 25, 2026
Source: NVD
CVE-2018-25369 MEDIUM - 6.2

Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers can inject malicious payloads exceeding 4108 bytes into the Host, Time Out, Packet Size, Pause, or Loops fields to trigger ...

Vendor: scanwith
Product: Visual Ping
Published: May 25, 2026
Source: NVD
CVE-2018-25367 MEDIUM - 6.2

NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom bro...

Vendor: NASA
Product: openVSP
Published: May 25, 2026
Source: NVD
CVE-2018-25363 MEDIUM - 4.3

Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms targeting tweetdel.php with tweet IDs and automatically submit them to delete arbitrary posts from aut...

Vendor: Fyffe
Product: PHP-Twitter-Clone
Published: May 25, 2026
Source: NVD
CVE-2018-25361 MEDIUM - 6.8

Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unl...

Vendor: Soroush
Product: Soroush IM Desktop App
Published: May 25, 2026
Source: NVD
CVE-2026-9451 MEDIUM - 6.3

A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been...

Published: May 25, 2026
Source: NVD
CVE-2026-9450 MEDIUM - 6.3

A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and ...

Published: May 25, 2026
Source: NVD
CVE-2026-9449 MEDIUM - 6.3

A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Published: May 25, 2026
Source: NVD
CVE-2026-9448 MEDIUM - 4.3

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the file /applyleave.php. Executing a manipulation of the argument ID can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed...

Published: May 25, 2026
Source: NVD
CVE-2026-46745 MEDIUM - 5.3

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authenticat...

Vendor: Apache Software Foundation
Product: Apache Airflow FAB provider
Published: May 25, 2026
Source: NVD
CVE-2026-9446 MEDIUM - 4.7

A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to ...

Published: May 25, 2026
Source: NVD
CVE-2026-9445 MEDIUM - 6.3

A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. T...

Published: May 25, 2026
Source: NVD
CVE-2026-9444 MEDIUM - 4.7

A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. T...

Published: May 25, 2026
Source: NVD
CVE-2026-9441 MEDIUM - 6.3

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated re...

Published: May 25, 2026
Source: NVD
CVE-2026-5223 MEDIUM - 5.3

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry.Β The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io ...

Vendor: rust-lang
Product: cargo
Published: May 25, 2026
Source: NVD
CVE-2026-5222 MEDIUM - 6.5

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credent...

Vendor: rust-lang
Product: cargo
Published: May 25, 2026
Source: NVD
CVE-2026-9440 MEDIUM - 6.3

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remote...

Published: May 25, 2026
Source: NVD