Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
Showing 2,921 - 2,940 of 13,527 CVEs
CVE-2026-9149 MEDIUM - 6.5

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could ...

Published: May 21, 2026
Source: NVD
CVE-2026-9150 MEDIUM - 6.5

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption...

Published: May 20, 2026
Source: NVD
CVE-2026-40102 MEDIUM - 6.5

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field R...

Vendor: makeplane
Product: plane
Published: May 20, 2026
Source: NVD
CVE-2026-40094 MEDIUM - 4.3

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and stores them in a peer contact book, eventually leading to address book crash. A PeerContact can l...

Vendor: nimiq
Product: core-rs-albatross
Published: May 20, 2026
Source: NVD
CVE-2026-9124 MEDIUM - 5.3

Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9122 MEDIUM - 6.5

Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9116 MEDIUM - 4.3

Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9115 MEDIUM - 4.3

Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9113 MEDIUM - 4.3

Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9110 MEDIUM - 4.2

Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9082 MEDIUM - 6.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from...

Vendor: drupal
Product: drupal
Published: May 20, 2026
Source: NVD
CVE-2026-47099 MEDIUM - 6.1

TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted JSON payload containing a malicious _constructor-name_ property value. The custom reviver passes the constructor name ...

Vendor: storybookjs
Product: telejson
Published: May 20, 2026
Source: NVD
CVE-2026-39311 MEDIUM - 6.8

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw where lack of SVG sanitization combined with a disabled Content Security Policy (CSP) and a publicly reachable backe...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-35016 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_query POST parameter directly into an HTML input field VALUE attribute. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35015 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the the_ticket GET parameter directly into a JavaScript variable assignment. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35014 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35013 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values through the thelat and thelng GET parameters directly into JavaScript variable assignments. Atta...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35012 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attack...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35011 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_call GET parameter directly into page output. Attackers can craft a malicious URL co...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35010 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a JavaScript variable assignment. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD