Total CVEs

132,176

Critical Severity

2,835

High Severity

10,141

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,741 - 2,760 of 28,581 CVEs
CVE-2026-44899 MEDIUM - 4.7

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^\d+(?:\.\d*)?"). When the validated value is not a plain integer, render_block_image() inse...

Vendor: pip
Product: mistune
Published: May 14, 2026
Source: GitHub
CVE-2026-44898 MEDIUM - 6.1

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used as href="#<id>") and the text value (used as the visible link label) are inserte...

Vendor: pip
Product: mistune
Published: May 14, 2026
Source: GitHub
CVE-2026-45292 MEDIUM - 5.3

OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation

Vendor: maven
Product: io.opentelemetry:opentelemetry-api
Published: May 14, 2026
Source: GitHub

Portainer missing authorization on custom template file endpoint, which exposes template content

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer: JWT accepted in URL query leaks tokens to logs and referers

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer has an endpoint security bypass via Swarm service create/update

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44882 HIGH - 8.1

Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44850 HIGH - 8.5

Portainer has a bind-mount restriction bypass via HostConfig.Mounts

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44885 MEDIUM - 5.5

Portainer has a path traversal in backup archive extraction that allows arbitrary file write

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer missing authorization on Docker plugin endpoints, which allows host RCE

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Vector Store No Permission Checks

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

Synapse pagination Denial of Service

Vendor: pip
Product: matrix-synapse
Published: May 14, 2026
Source: GitHub

Synapse CPU starvation (Denial of Service)

Vendor: pip
Product: matrix-synapse
Published: May 14, 2026
Source: GitHub