Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,810
Quick preset (or use dates below)
Clear Filters
Showing 261 - 280 of 1,466 CVEs

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Vendor: JetBrains
Product: YouTrack
Published: May 29, 2026
Source: NVD

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.use...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a pr...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a pr...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init invocation, a key value entry...

Vendor: OpenSC
Product: OpenSC
Published: May 29, 2026
Source: NVD

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field long...

Vendor: OpenSC
Product: OpenSC
Published: May 29, 2026
Source: NVD

A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL query parameters during POST requests to the GitLab endpoint. This insecure transmission can lead t...

Vendor: Red Hat
Product: Red Hat Quay 3
Published: May 29, 2026
Source: NVD
CVE-2026-9991 LOW - 3.1

Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9959 LOW - 3.1

Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9950 LOW - 3.1

Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9944 LOW - 3.1

Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9920 LOW - 3.1

Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-6816 LOW - 3.8

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.

Vendor: tfa_basic_plugins_project
Product: tfa_basic_plugins
Published: May 28, 2026
Source: NVD

Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: May 28, 2026
Source: NVD

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mode can survive single-user -> multi-user migration even when the device record has userId = null. I...

Vendor: Mintplex-Labs
Product: anything-llm
Published: May 28, 2026
Source: NVD

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only the top-level source and destination paths. The recursive copy helper then descends into child entrie...

Vendor: Mintplex-Labs
Product: anything-llm
Published: May 28, 2026
Source: NVD

symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form

Vendor: composer
Product: symfony/polyfill
Published: May 28, 2026
Source: GitHub

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD

Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.

Vendor: Canonical
Product: Ubuntu Linux
Published: May 28, 2026
Source: NVD