Total CVEs

133,052

Critical Severity

2,915

High Severity

10,581

Last 7 Days

2,067
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,821 - 2,840 of 29,457 CVEs
CVE-2026-37281 CRITICAL - 9.8

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

Published: May 19, 2026
Source: NVD
CVE-2026-31072 CRITICAL - 9.8

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically importing modules and...

Published: May 19, 2026
Source: NVD
CVE-2026-31071 CRITICAL - 9.1

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescrip...

Published: May 19, 2026
Source: NVD
CVE-2026-31070 CRITICAL - 9.8

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body

Published: May 19, 2026
Source: NVD
CVE-2026-31069 HIGH - 8.8

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although fi...

Published: May 19, 2026
Source: NVD
CVE-2026-30118 CRITICAL - 9.8

scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend server to send HTTP requests to attacker-controlled URLs, leading to authentica...

Published: May 19, 2026
Source: NVD
CVE-2026-30117 CRITICAL - 9.8

scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file.

Published: May 19, 2026
Source: NVD

Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs

Vendor: pip
Product: strawberry-graphql
Published: May 19, 2026
Source: GitHub
CVE-2026-45738 HIGH - 7.3

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

Vendor: go
Product: github.com/argoproj/argo-cd/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-45737 MEDIUM - 6.3

Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations

Vendor: go
Product: github.com/argoproj/argo-cd/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-45713 HIGH - 7.5

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

Vendor: go
Product: github.com/axllent/mailpit
Published: May 19, 2026
Source: GitHub
CVE-2026-45712 MEDIUM - 5.9

Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)

Vendor: go
Product: github.com/axllent/mailpit
Published: May 19, 2026
Source: GitHub
CVE-2026-45711 MEDIUM - 5.9

Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs

Vendor: go
Product: github.com/axllent/mailpit
Published: May 19, 2026
Source: GitHub
CVE-2026-45709 MEDIUM - 5.8

Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer

Vendor: go
Product: github.com/axllent/mailpit
Published: May 19, 2026
Source: GitHub
CVE-2026-45692 MEDIUM - 5.4

Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: May 19, 2026
Source: GitHub

Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)

Vendor: npm
Product: @nuxt/rspack-builder
Published: May 19, 2026
Source: GitHub

Nuxt: Reflected XSS in `navigateTo()` external redirect

Vendor: npm
Product: nuxt
Published: May 19, 2026
Source: GitHub
CVE-2026-45758 CRITICAL - 9.6

Malicious code in guardrails-ai 0.10.1 (supply chain compromise)

Vendor: pip
Product: guardrails-ai
Published: May 19, 2026
Source: GitHub
CVE-2026-45581 MEDIUM - 5.5

fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode

Vendor: maven
Product: org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim
Published: May 19, 2026
Source: GitHub

zrok copy writes attacker-controlled WebDAV paths outside the destination root

Vendor: go
Product: github.com/openziti/zrok/v2
Published: May 19, 2026
Source: GitHub