Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,761 - 2,780 of 13,146 CVEs
CVE-2026-39966 MEDIUM - 6.5

TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions to any authenticated user who references a target bot ID in a Typebot Link block, regardless of workspace ownership, leading to IDOR. The authorization check uses Array.filter() wit...

Published: May 22, 2026
Source: NVD
CVE-2026-42627 MEDIUM - 6.2

In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model optimization. The overflow occurs when multiplying tensor dimensions us...

Published: May 22, 2026
Source: NVD
CVE-2026-39964 MEDIUM - 5.4

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme. A bot author can set a link URL to javascript:PAYLOAD, which executes in the visitor's browser ...

Vendor: npm
Product: @typebot.io/js
Published: May 22, 2026
Source: NVD

Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance

Vendor: pip
Product: Flask-Security-Too
Published: May 22, 2026
Source: GitHub
CVE-2026-42626 MEDIUM - 5.9

HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can establish a persistent connection to port 9100 and send keep-alive packets, causing the printer'...

Published: May 22, 2026
Source: NVD
CVE-2026-36227 MEDIUM - 6.5

Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter

Published: May 22, 2026
Source: NVD
CVE-2026-36226 MEDIUM - 6.1

Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component

Published: May 22, 2026
Source: NVD
CVE-2026-28735 MEDIUM - 5.4

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub author...

Vendor: mattermost
Product: mattermost_server
Published: May 22, 2026
Source: NVD
CVE-2026-28444 MEDIUM - 6.5

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verifying that the result belongs to the authorized typebot, leading to IDOR. An authenticated attacker can...

Published: May 22, 2026
Source: NVD
CVE-2026-9251 MEDIUM - 5.4

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's data via a crafted status change request. This issue affects : * Devolut...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9246 MEDIUM - 4.3

Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 th...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9245 MEDIUM - 5.0

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Dev...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9224 MEDIUM - 4.3

Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3....

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9223 MEDIUM - 4.3

Missing authorization in the vault import feature in Devolutions ServerΒ Β 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-5171 MEDIUM - 4.3

Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 th...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-42506 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-42502 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-27136 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-25681 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-25680 MEDIUM - 6.5

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD