Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
Showing 2,881 - 2,900 of 12,982 CVEs
CVE-2026-3623 HIGH - 7.8

IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s password. Successful ...

Vendor: ibm
Product: netezza_performance_server_replication_services
Published: May 27, 2026
Source: NVD
CVE-2026-3366 HIGH - 7.5

IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) ...

Vendor: ibm
Product: infosphere_optim_test_data_fabrication
Published: May 27, 2026
Source: NVD
CVE-2026-38427 HIGH - 7.3

An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream is stored in a uint16_t variable; values above 65535 wrap around, causing allocation of a smaller buffer than the data actually re...

Published: May 27, 2026
Source: NVD
CVE-2026-38426 HIGH - 7.3

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.boundary[40], strcpy() function.

Published: May 27, 2026
Source: NVD
CVE-2026-38422 HIGH - 7.3

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/tasmota_xdrv_driver/xdrv_10_scripter.ino, fetch_jpg() function.

Published: May 27, 2026
Source: NVD
CVE-2026-36540 HIGH - 7.3

Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrap...

Published: May 27, 2026
Source: NVD
CVE-2026-36539 HIGH - 7.3

Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any attacker on the LAN can send a single HTTP GET request and instantly retrieve administrator credentials, WiFi password...

Published: May 27, 2026
Source: NVD
CVE-2026-36538 HIGH - 7.3

Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacker with access to the device to authenticate as root and gain full control of the underlying operating...

Published: May 27, 2026
Source: NVD
CVE-2026-36045 HIGH - 7.3

picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.

Published: May 27, 2026
Source: NVD
CVE-2026-36044 HIGH - 8.8

@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js ...

Published: May 27, 2026
Source: NVD
CVE-2026-1933 HIGH - 7.1

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only e...

Vendor: redhat
Product: openshift_container_platform
Published: May 27, 2026
Source: NVD
CVE-2026-1718 HIGH - 7.1

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.

Vendor: ibm
Product: db2
Published: May 27, 2026
Source: NVD
CVE-2024-56462 HIGH - 7.2

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.

Vendor: IBM
Product: QRadar
Published: May 27, 2026
Source: NVD
CVE-2026-48906 HIGH - 8.1

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.

Vendor: tassos.gr
Product: Novarain/Tassos Framework (plg_system_nrframework), Convert Forms, EngageBox, Google Structured Data, Advanced Custom Fields, Smile Pack, Tassos Code Snippets, MailChimp Auto-Subscribe
Published: May 27, 2026
Source: NVD
CVE-2026-45843 HIGH - 8.2

In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neither helper bounds-checks against isize, a...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-42762 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows DOM-Based XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: May 27, 2026
Source: NVD
CVE-2026-42760 HIGH - 7.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25.

Vendor: revmakx
Product: Backup and Staging by WP Time Capsule
Published: May 27, 2026
Source: NVD
CVE-2026-42759 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Super Assistent amazonsimpleadmin allows Stored XSS.This issue affects Affiliate Super Assistent: from n/a through <= 1.10.1.

Vendor: Timo
Product: Affiliate Super Assistent
Published: May 27, 2026
Source: NVD
CVE-2026-42754 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon favicon-by-realfavicongenerator allows Reflected XSS.This issue affects Favicon: from n/a through <= 1.3.46.

Vendor: phbernard
Product: Favicon
Published: May 27, 2026
Source: NVD
CVE-2026-42753 HIGH - 7.3

Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.

Vendor: WC Lovers
Product: WCFM Membership
Published: May 27, 2026
Source: NVD