Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,861 - 2,880 of 12,512 CVEs
CVE-2026-24212 HIGH - 7.5

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Isaac Launchable
Published: May 26, 2026
Source: NVD
CVE-2026-24162 HIGH - 7.8

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: Merlin Transformers4Rec
Published: May 26, 2026
Source: NVD
CVE-2026-48692 HIGH - 8.1

FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line 477) and a source code comment explicitly acknowledges 'Listen on the given address with...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48688 HIGH - 7.5

FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks to avoid reads ...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-43935 HIGH - 8.1

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. This can lead to phishing attacks, account takeover, or...

Vendor: e107inc
Product: e107
Published: May 26, 2026
Source: NVD
CVE-2026-25112 HIGH - 7.8

A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.

Vendor: Genetec Inc.
Product: Genetec RabbitMQ, Genetec Mission Control, Genetec Sipelia, Genetec Industrial IoT, Genetec Airport Operational Manager, Genetec Restricted Security Area, Genetec Inter-System Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-9552 HIGH - 7.3

A security flaw has been discovered in Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exploit has been releas...

Published: May 26, 2026
Source: NVD
CVE-2026-9551 HIGH - 7.3

A vulnerability was identified in Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The manipulation of the argument Value leads to sql injection. It is possible to initiate the attack remo...

Published: May 26, 2026
Source: NVD
CVE-2026-9550 HIGH - 7.3

A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead to path traversal. Th...

Published: May 26, 2026
Source: NVD
CVE-2026-4480 HIGH - 8.5

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this ...

Vendor: redhat
Product: openshift_container_platform
Published: May 26, 2026
Source: NVD
CVE-2026-46368 HIGH - 8.8

luci-app-https-dns-proxy through 2025.12.29-5 โ€” an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default โ€” contains a command injection vulnerability in the setInitAction function. An authenticated user holdi...

Vendor: mossdef-org
Product: luci-app-https-dns-proxy
Published: May 26, 2026
Source: NVD
CVE-2026-45082 HIGH - 7.6

Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward ...

Vendor: karakeep-app
Product: karakeep
Published: May 26, 2026
Source: NVD
CVE-2026-42785 HIGH - 7.2

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands i...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD
CVE-2026-42425 HIGH - 7.2

OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/Da...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD
CVE-2026-40034 HIGH - 7.8

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attack...

Vendor: gitoxide
Product: gitoxide
Published: May 26, 2026
Source: NVD
CVE-2026-40033 HIGH - 8.8

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry d...

Vendor: FreeRDP
Product: FreeRDP
Published: May 26, 2026
Source: NVD
CVE-2026-9544 HIGH - 7.3

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to...

Published: May 26, 2026
Source: NVD
CVE-2026-48134 HIGH - 7.6

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to...

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48133 HIGH - 7.5

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48132 HIGH - 7.4

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negot...

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD