Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

986
Quick preset (or use dates below)
Clear Filters
Showing 2,961 - 2,980 of 12,982 CVEs
CVE-2026-9606 HIGH - 7.3

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be us...

Published: May 27, 2026
Source: NVD
CVE-2026-9605 HIGH - 7.3

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be u...

Published: May 27, 2026
Source: NVD
CVE-2026-9312 HIGH - 8.2

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request par...

Vendor: github
Product: enterprise_server
Published: May 27, 2026
Source: NVD

Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass

Vendor: npm
Product: fuxa-server
Published: May 26, 2026
Source: GitHub

FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue

Vendor: npm
Product: fuxa-server
Published: May 26, 2026
Source: GitHub

FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

Vendor: npm
Product: @frangoteam/fuxa
Published: May 26, 2026
Source: GitHub
CVE-2026-42462 HIGH - 7.0

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linke...

Vendor: npm
Product: @fedify/fedify
Published: May 26, 2026
Source: GitHub
CVE-2026-42089 HIGH - 8.6

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass at...

Vendor: npm
Product: yeoman-environment
Published: May 26, 2026
Source: GitHub
CVE-2026-9584 HIGH - 7.3

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and ...

Published: May 26, 2026
Source: NVD
CVE-2026-5260 HIGH - 8.2

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

Published: May 26, 2026
Source: NVD
CVE-2026-44905 HIGH - 7.5

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically val...

Vendor: riebl
Product: vanetza
Published: May 26, 2026
Source: NVD
CVE-2026-43988 HIGH - 7.5

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing corrupted ASN.1/OER structures (e.g., invalid length fi...

Vendor: riebl
Product: vanetza
Published: May 26, 2026
Source: NVD
CVE-2026-42013 HIGH - 8.2

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 26, 2026
Source: NVD
CVE-2026-42012 HIGH - 7.1

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 26, 2026
Source: NVD
CVE-2025-46284 HIGH - 7.0

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43306 HIGH - 7.8

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2026-9580 HIGH - 7.3

A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may ...

Published: May 26, 2026
Source: NVD