Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
Showing 2,761 - 2,780 of 12,982 CVEs
CVE-2026-2374 HIGH - 7.2

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['P...

Published: May 28, 2026
Source: NVD
CVE-2026-8915 HIGH - 8.8

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.

Vendor: samsung
Product: escargot
Published: May 28, 2026
Source: NVD
CVE-2026-46414 HIGH - 8.8

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46402 HIGH - 8.1

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause U...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-45322 HIGH - 7.8

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD

compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 27, 2026
Source: GitHub
CVE-2026-47717 HIGH - 7.5

FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations

Vendor: npm
Product: fuxa-server
Published: May 27, 2026
Source: GitHub

Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs

Vendor: go
Product: github.com/kata-containers/kata-containers
Published: May 27, 2026
Source: GitHub

Pimcore has a CustomReports Share Bypass

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub
CVE-2026-9208 HIGH - 8.8

Tanium addressed an unauthorized code execution vulnerability in Connect.

Vendor: tanium
Product: connect
Published: May 27, 2026
Source: NVD
CVE-2026-45332 HIGH - 7.5

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collectio...

Vendor: composer
Product: automad/automad
Published: May 27, 2026
Source: GitHub
CVE-2026-47269 HIGH - 7.4

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb's deny_remote feature checks utmpx ut_addr_v6 to detect whether an authentication request originates from a remote session. The outer guard was if (utent->ut_addr_v6[0] != 0), which on...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44713 HIGH - 8.8

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment variable, splits it on commas, and interpolates the socket-path component directly into a shell command passed to popen(). Because the value is placed...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44712 HIGH - 8.2

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-conf --reset-pads is run. A USB device with a crafted filesystem UUID (some controllers allow this) can inject the pay...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44711 HIGH - 7.9

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44709 HIGH - 7.8

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set environment variables before pamusb-pinentry is invoked ca...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD

Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener

Vendor: composer
Product: symfony/monolog-bridge
Published: May 27, 2026
Source: GitHub

Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address

Vendor: composer
Product: symfony/mime
Published: May 27, 2026
Source: GitHub
CVE-2026-8361 HIGH - 7.5

A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome

Published: May 27, 2026
Source: NVD
CVE-2026-8360 HIGH - 7.5

Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being de...

Published: May 27, 2026
Source: NVD