Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,881 - 2,900 of 12,512 CVEs
CVE-2026-48131 HIGH - 8.1

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2025-11482 HIGH - 7.5

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service.

Vendor: B&R Industrial Automation GmbH
Product: PPT30 Operating System
Published: May 26, 2026
Source: NVD
CVE-2026-39661 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18.

Vendor: Magentech
Product: SW Core
Published: May 26, 2026
Source: NVD
CVE-2026-25713 HIGH - 7.8

MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 26, 2026
Source: NVD
CVE-2026-25104 HIGH - 7.8

MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 26, 2026
Source: NVD
CVE-2026-8047 HIGH - 7.5

The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.

Published: May 26, 2026
Source: NVD
CVE-2026-8046 HIGH - 8.1

The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.

Published: May 26, 2026
Source: NVD
CVE-2026-44469 HIGH - 7.8

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before insta...

Vendor: CODESYS
Product: CODESYS Development System
Published: May 26, 2026
Source: NVD
CVE-2026-44468 HIGH - 7.8

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary co...

Vendor: CODESYS
Product: CODESYS Development System
Published: May 26, 2026
Source: NVD
CVE-2026-9496 HIGH - 7.5

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing exces...

Published: May 26, 2026
Source: NVD
CVE-2026-9495 HIGH - 7.3

Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attack...

Published: May 26, 2026
Source: NVD
CVE-2026-9528 HIGH - 7.3

A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be us...

Published: May 26, 2026
Source: NVD
CVE-2026-9526 HIGH - 7.3

A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used...

Published: May 26, 2026
Source: NVD
CVE-2026-9525 HIGH - 7.3

A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may b...

Published: May 26, 2026
Source: NVD
CVE-2026-9523 HIGH - 7.3

A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree. Performing a manipulation of the argument sor...

Published: May 26, 2026
Source: NVD
CVE-2026-9538 HIGH - 7.5

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no up...

Vendor: archive\
Product: \
Published: May 26, 2026
Source: NVD
CVE-2026-9521 HIGH - 7.3

A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exp...

Published: May 26, 2026
Source: NVD
CVE-2026-42497 HIGH - 7.5

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim fi...

Vendor: BINGOS
Product: Archive::Tar
Published: May 26, 2026
Source: NVD
CVE-2026-9517 HIGH - 7.3

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be e...

Published: May 26, 2026
Source: NVD
CVE-2026-48837 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.

Vendor: Unlimited Elements
Product: Unlimited Elements For Elementor
Published: May 25, 2026
Source: NVD