Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,016
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,941 - 2,960 of 13,146 CVEs
CVE-2026-35009 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35008 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into an HTML attribute. Attackers can craft a maliciou...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35007 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id GET parameter directly into an HTML attribute. Attackers can craft a malicious ...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-2813 MEDIUM - 4.7

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended, untrusted site, resulting ...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD
CVE-2026-2812 MEDIUM - 5.3

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This is...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD
CVE-2026-26028 MEDIUM - 6.1

CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of <iframe>, <video>, and <audio&...

Vendor: cryptpad
Product: cryptpad
Published: May 20, 2026
Source: NVD
CVE-2026-30691 MEDIUM - 6.1

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode

Published: May 20, 2026
Source: NVD
CVE-2026-20240 MEDIUM - 6.5

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the β€˜admin’ or β€˜power’ Splunk roles could cause a Denial of ...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-20238 MEDIUM - 6.5

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configu...

Vendor: Splunk
Product: Splunk AI Toolkit
Published: May 20, 2026
Source: NVD
CVE-2026-9101 MEDIUM - 4.3

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

Published: May 20, 2026
Source: NVD
CVE-2026-9100 MEDIUM - 5.9

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process ...

Published: May 20, 2026
Source: NVD
CVE-2026-9087 MEDIUM - 6.4

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Published: May 20, 2026
Source: NVD
CVE-2026-44924 MEDIUM - 5.4

InfoScale VIOM 9.1.3 allows XSS.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-44923 MEDIUM - 6.5

SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-20206 MEDIUM - 6.3

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEy...

Vendor: Cisco
Product: Cisco ThousandEyes Enterprise Agent
Published: May 20, 2026
Source: NVD
CVE-2026-20199 MEDIUM - 4.7

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authentica...

Vendor: Cisco
Product: Cisco ThousandEyes Enterprise Agent
Published: May 20, 2026
Source: NVD
CVE-2026-20171 MEDIUM - 6.8

A vulnerability in the Border Gateway Protocol (BGP)&nbsp;enforce-first-as feature of&nbsp;Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of servic...

Vendor: Cisco
Product: Cisco NX-OS Software
Published: May 20, 2026
Source: NVD
CVE-2026-8488 MEDIUM - 4.3

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Vendor: progress
Product: moveit_automation
Published: May 20, 2026
Source: NVD
CVE-2026-8487 MEDIUM - 6.5

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Vendor: progress
Product: moveit_automation
Published: May 20, 2026
Source: NVD
CVE-2026-8486 MEDIUM - 5.3

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Vendor: progress
Product: moveit_automation
Published: May 20, 2026
Source: NVD