Total CVEs

133,052

Critical Severity

2,915

High Severity

10,581

Last 7 Days

2,059
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,901 - 2,920 of 29,457 CVEs

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within database user context. The vendor was notified early about this vulnerability, but didn't respond...

Vendor: Sparx Systems
Product: Pro Cloud Server
Published: May 19, 2026
Source: NVD
CVE-2026-23558 HIGH - 7.8

The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table version change from v2 to v1 in parallel with mapping the status page(s) via XENMEM_add_to_physmap. Some of the status pages may then be freed while m...

Vendor: Xen
Product: Xen
Published: May 19, 2026
Source: NVD
CVE-2026-23557 MEDIUM - 6.5

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will happen, as assert() is doing nothing in this case. Note that the default is not to define NDEBUG for xen...

Vendor: Xen
Product: Xen
Published: May 19, 2026
Source: NVD
CVE-2025-40904 MEDIUM - 6.5

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote ...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40903 MEDIUM - 5.9

A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected sch...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40902 MEDIUM - 5.9

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing th...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40901 MEDIUM - 5.9

A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected ide...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40900 MEDIUM - 4.6

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to impor...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.

Vendor: The Qt Company
Product: Qt
Published: May 19, 2026
Source: NVD
CVE-2026-8912 HIGH - 7.5

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unaut...

Published: May 19, 2026
Source: NVD
CVE-2026-4883 CRITICAL - 9.8

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php...

Published: May 19, 2026
Source: NVD

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied...

Published: May 19, 2026
Source: NVD
CVE-2026-7571 HIGH - 7.1

A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can obtain an access token tha...

Published: May 19, 2026
Source: NVD
CVE-2026-7507 HIGH - 7.5

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which...

Published: May 19, 2026
Source: NVD
CVE-2026-7504 HIGH - 8.1

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further att...

Published: May 19, 2026
Source: NVD
CVE-2026-7307 HIGH - 7.5

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes...

Published: May 19, 2026
Source: NVD
CVE-2026-4630 MEDIUM - 6.8

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same ...

Published: May 19, 2026
Source: NVD
CVE-2026-45442 MEDIUM - 4.3

Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3.

Vendor: Brainstorm Force
Product: Presto Player
Published: May 19, 2026
Source: NVD
CVE-2026-43493 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that value and filtering out EINPROGRESS notifications.

Vendor: Linux
Product: Linux
Published: May 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when subtracting "lzeros" from the unsigned "nbytes". For this to happen, the sc...

Vendor: Linux
Product: Linux
Published: May 19, 2026
Source: NVD