Total CVEs

133,052

Critical Severity

2,915

High Severity

10,581

Last 7 Days

2,067
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,761 - 2,780 of 29,457 CVEs
CVE-2026-32814 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitializ...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-32741 HIGH - 7.1

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, d...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2025-57798 MEDIUM - 5.5

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial of Service (DoS) vulnerability in the title input functionality due to a lack of proper length validation. This flaw allows an attacker to cause an Out...

Vendor: laurent22
Product: joplin
Published: May 19, 2026
Source: NVD

@angular/platform-server: SSRF via Hostname Hijacking

Vendor: npm
Product: @angular/platform-server
Published: May 19, 2026
Source: GitHub
CVE-2026-46415 HIGH - 8.2

Caddy Defender trusted proxy client IP bypass

Vendor: go
Product: pkg.jsn.cam/caddy-defender
Published: May 19, 2026
Source: GitHub
CVE-2026-46412 CRITICAL - 10.0

Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) โ€” Mini Shai-Hulud worm

Vendor: npm
Product: @beproduct/nestjs-auth
Published: May 19, 2026
Source: GitHub
CVE-2026-42526 MEDIUM - 5.3

In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the same path as another team's team-scoped secret when the caller had...

Vendor: Apache Software Foundation
Product: Apache Airflow Amazon provider
Published: May 19, 2026
Source: NVD
CVE-2026-32740 HIGH - 8.8

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-32739 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout a...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-27173 HIGH - 8.7

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Ai...

Vendor: Apache Software Foundation
Product: Apache Airflow CNCF Kubernetes provider
Published: May 19, 2026
Source: NVD

FileBrowser Quantum: unauthenticated user share share info

Vendor: go
Product: github.com/gtsteffaniak/filebrowser/backend
Published: May 19, 2026
Source: GitHub
CVE-2026-46374 HIGH - 7.5

SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser

Vendor: pip
Product: sqlfluff
Published: May 19, 2026
Source: GitHub
CVE-2026-46373 HIGH - 7.5

SQLFluff: Recursive Stack Overflow in Parser

Vendor: pip
Product: sqlfluff
Published: May 19, 2026
Source: GitHub
CVE-2026-46372 HIGH - 8.5

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which accepts attacker-controlled baseUrl and uses it direc...

Vendor: npm
Product: sillytavern
Published: May 19, 2026
Source: GitHub
CVE-2026-46378 HIGH - 7.5

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

Vendor: go
Product: github.com/tomwright/dasel/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-46377 HIGH - 7.5

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

Vendor: go
Product: github.com/tomwright/dasel/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-45783 HIGH - 7.5

@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes

Vendor: npm
Product: @libp2p/kad-dht
Published: May 19, 2026
Source: GitHub
CVE-2026-46354 CRITICAL - 9.1

Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft

Vendor: go
Product: github.com/coder/coder/v2
Published: May 19, 2026
Source: GitHub

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Vendor: npm
Product: nuxt
Published: May 19, 2026
Source: GitHub
CVE-2026-46338 MEDIUM - 4.3

Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path

Vendor: pip
Product: pymdown-extensions
Published: May 19, 2026
Source: GitHub