Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,761 - 2,780 of 12,494 CVEs
CVE-2026-6268 HIGH - 7.1

The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against ...

Published: May 27, 2026
Source: NVD
CVE-2026-48962 HIGH - 7.3

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through ...

Vendor: PMQS
Product: IO::Compress
Published: May 27, 2026
Source: NVD
CVE-2026-48961 HIGH - 7.3

IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, caus...

Vendor: PMQS
Product: IO::Compress
Published: May 27, 2026
Source: NVD
CVE-2026-48959 HIGH - 7.5

IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration....

Vendor: PMQS
Product: IO::Uncompress::Unzip
Published: May 27, 2026
Source: NVD
CVE-2026-2253 HIGH - 7.7

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, includingย 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

Published: May 27, 2026
Source: NVD
CVE-2026-9632 HIGH - 8.8

A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible t...

Published: May 27, 2026
Source: NVD
CVE-2026-9631 HIGH - 8.8

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer ov...

Published: May 27, 2026
Source: NVD
CVE-2026-9628 HIGH - 8.8

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer ove...

Published: May 27, 2026
Source: NVD
CVE-2026-9627 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely...

Published: May 27, 2026
Source: NVD
CVE-2026-9207 HIGH - 8.8

Tanium addressed an unauthorized code execution vulnerability in Connect.

Vendor: tanium
Product: connect
Published: May 27, 2026
Source: NVD
CVE-2026-49014 HIGH - 7.4

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribu...

Vendor: GDAL
Product: GDAL
Published: May 27, 2026
Source: NVD

@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters

Vendor: npm
Product: @hapi/content
Published: May 27, 2026
Source: GitHub
CVE-2026-44741 HIGH - 8.8

Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter

Vendor: composer
Product: pimcore/admin-ui-classic-bundle
Published: May 27, 2026
Source: GitHub
CVE-2026-44739 HIGH - 8.7

Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub
CVE-2026-44705 HIGH - 8.2

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../...

Vendor: npm
Product: tmp
Published: May 27, 2026
Source: GitHub
CVE-2026-9606 HIGH - 7.3

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be us...

Published: May 27, 2026
Source: NVD
CVE-2026-9605 HIGH - 7.3

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be u...

Published: May 27, 2026
Source: NVD
CVE-2026-9312 HIGH - 8.2

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request par...

Vendor: github
Product: enterprise_server
Published: May 27, 2026
Source: NVD

Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub