Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,861 - 2,880 of 13,146 CVEs
CVE-2026-46543 MEDIUM - 5.3

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls get_epoch_chunks which iterat...

Vendor: rust
Product: nimiq-blockchain
Published: May 21, 2026
Source: GitHub
CVE-2026-46542 MEDIUM - 4.3

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. Ed25519PublicKey::delinearize() in keys/src/multisig/mod.rs called .unwr...

Vendor: rust
Product: nimiq-keys
Published: May 21, 2026
Source: GitHub
CVE-2026-46539 MEDIUM - 5.9

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven causes the function to return true without performing any cryptographic verification when get_interlink_hops yi...

Vendor: rust
Product: nimiq-primitives
Published: May 21, 2026
Source: GitHub
CVE-2026-48249 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for outbound HTTPS requests issued during the mobile (RouteMate) login flow. ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48248 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for outbound HTTPS requests issued during the login/authentication flow. An attacker po...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48247 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for general-purpose outbound HTTPS requests issued by the shared helper functions. ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48246 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker pos...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48245 MEDIUM - 5.3

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Clo...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48244 MEDIUM - 5.3

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Goog...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48243 MEDIUM - 5.3

Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can extract the key and use it to make third-party API calls billed to or rate-limited against the original ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48230 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the multiple POST parameters (mdbhost, mdbdb, mdbuser, mdbpassword, mdbprefix, t...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48229 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into HTML form hidden input value attributes. Attack...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48228 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id and ticket_id GET parameters directly into an HTML form action URL. Attackers can...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48227 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id and ticket_id GET parameters directly into an HTML form action URL. Attackers can c...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48226 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ref and mode_orig POST parameters directly into HTML form hidden input value attribut...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48225 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the _type POST parameter directly into an HTML form hidden input value attribute. Attackers ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48224 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. Att...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48223 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. A...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48222 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. Att...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48221 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. At...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD