Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,949
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,821 - 2,840 of 12,494 CVEs
CVE-2026-44669 HIGH - 8.7

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts wit...

Vendor: factionsecurity
Product: faction
Published: May 26, 2026
Source: NVD
CVE-2026-44667 HIGH - 8.7

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification file preview flows. User-supplied filename values are persisted and then rendered into HTML and attri...

Vendor: factionsecurity
Product: faction
Published: May 26, 2026
Source: NVD
CVE-2026-24200 HIGH - 7.0

NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24196 HIGH - 7.1

NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver
Published: May 26, 2026
Source: NVD
CVE-2026-24195 HIGH - 7.1

NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Guest driver
Published: May 26, 2026
Source: NVD
CVE-2026-24194 HIGH - 7.8

NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execu...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver
Published: May 26, 2026
Source: NVD
CVE-2026-24193 HIGH - 7.8

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla
Published: May 26, 2026
Source: NVD
CVE-2026-24192 HIGH - 7.8

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data ...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24191 HIGH - 7.8

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24190 HIGH - 7.8

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and ...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla
Published: May 26, 2026
Source: NVD
CVE-2026-24187 HIGH - 8.8

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-9562 HIGH - 7.3

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been...

Published: May 26, 2026
Source: NVD
CVE-2026-8850 HIGH - 7.5

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-48901 HIGH - 7.5

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48897 HIGH - 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48896 HIGH - 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48864 HIGH - 7.8

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can le...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, Red Hat Update Infrastructure 4 for Cloud Providers
Published: May 26, 2026
Source: NVD
CVE-2026-48697 HIGH - 7.4

FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but neve...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48690 HIGH - 7.1

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(fastnetmon_pcap_...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48126 HIGH - 8.2

Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the value of the client-s...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD