Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
Showing 2,961 - 2,980 of 13,527 CVEs
CVE-2026-4293 MEDIUM - 5.3

The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.

Published: May 20, 2026
Source: NVD
CVE-2023-7346 MEDIUM - 4.0

Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that...

Published: May 20, 2026
Source: NVD
CVE-2026-46431 MEDIUM - 4.3

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's Origin. Because EventSource does not preflight and does not send cookies, the wildcard is su...

Vendor: go
Product: github.com/xyproto/algernon
Published: May 20, 2026
Source: GitHub
CVE-2026-46430 MEDIUM - 4.3

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553&...

Vendor: go
Product: github.com/xyproto/algernon
Published: May 20, 2026
Source: GitHub
CVE-2026-46420 MEDIUM - 5.6

Setup PHP: Command Injection in Repository-Derived PHP Version Resolution

Vendor: actions
Product: shivammathur/setup-php
Published: May 20, 2026
Source: GitHub

rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK automatically loads .rtk/filters.toml from the working directory with highest priority and without user notification. An at...

Vendor: rust
Product: rtk
Published: May 20, 2026
Source: GitHub
CVE-2026-8485 MEDIUM - 5.9

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Vendor: progress
Product: moveit_automation
Published: May 20, 2026
Source: NVD
CVE-2026-21836 MEDIUM - 6.5

The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query.  This could enable an authenticated attacker to view sensitive data.

Vendor: HCLSoftware
Product: DominoIQ
Published: May 20, 2026
Source: NVD
CVE-2026-5950 MEDIUM - 5.3

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through ...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-45498 MEDIUM - 4.0

Microsoft Defender Denial of Service Vulnerability

Vendor: microsoft
Product: defender_antimalware_platform
Published: May 20, 2026
Source: NVD
CVE-2026-45443 MEDIUM - 5.0

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1.

Vendor: ADD-ONS.ORG
Product: PDF for Elementor Forms + Drag And Drop Template Builder
Published: May 20, 2026
Source: NVD
CVE-2026-3592 MEDIUM - 5.3

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 throu...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-27424 MEDIUM - 4.3

Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.

Vendor: WP Chill
Product: Image Photo Gallery Final Tiles Grid
Published: May 20, 2026
Source: NVD
CVE-2026-27405 MEDIUM - 6.5

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.

Vendor: Magepeople inc.
Product: WpBookingly
Published: May 20, 2026
Source: NVD
CVE-2026-24573 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0.

Vendor: Themeisle
Product: Visualizer
Published: May 20, 2026
Source: NVD
CVE-2025-31973 MEDIUM - 4.0

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

Vendor: HCL
Product: BigFix Service Management (SM)
Published: May 20, 2026
Source: NVD
CVE-2026-25602 MEDIUM - 4.4

Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: th...

Vendor: Mesalvo
Product: Meona Client Launcher Component, Meona Server Component
Published: May 20, 2026
Source: NVD
CVE-2026-0857 MEDIUM - 6.0

Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

Published: May 20, 2026
Source: NVD
CVE-2026-6728 MEDIUM - 5.3

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected pos...

Published: May 20, 2026
Source: NVD
CVE-2026-44608 MEDIUM - 5.9

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash....

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD