Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
Showing 2,981 - 3,000 of 12,982 CVEs
CVE-2026-8676 HIGH - 8.8

An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.

Published: May 26, 2026
Source: NVD
CVE-2026-44847 HIGH - 7.5

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns (None, {}), which Django REST Framework interprets as successful authe...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD
CVE-2025-14361 HIGH - 7.1

Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1.

Vendor: AA-Team
Product: Woocommerce Envato Affiliates
Published: May 26, 2026
Source: NVD
CVE-2026-48048 HIGH - 7.5

XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests

Vendor: maven
Product: org.xwiki.platform:xwiki-platform-livetable-ui
Published: May 26, 2026
Source: GitHub
CVE-2026-9575 HIGH - 7.3

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has ...

Published: May 26, 2026
Source: NVD
CVE-2026-9574 HIGH - 7.3

A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the argument studentId/cid can lead to sql injection. The attack can be launched remotely. The exploit has...

Published: May 26, 2026
Source: NVD
CVE-2026-9573 HIGH - 7.3

A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation of the argument studentId results in sql injection. The attack can be initiated remotely. The exploit ...

Published: May 26, 2026
Source: NVD
CVE-2026-8890 HIGH - 8.2

code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP header. The middleware in middleware.ts skips identity header generation when an Auth-Key head...

Published: May 26, 2026
Source: NVD
CVE-2026-4051 HIGH - 7.2

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.

Vendor: ibm
Product: engineering_lifecycle_management
Published: May 26, 2026
Source: NVD
CVE-2026-3603 HIGH - 7.1

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit t...

Vendor: ibm
Product: engineering_lifecycle_management
Published: May 26, 2026
Source: NVD
CVE-2026-9560 HIGH - 7.8

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

Vendor: openvpn
Product: connect
Published: May 26, 2026
Source: NVD
CVE-2026-9170 HIGH - 7.5

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to denial of service and a potential remote code execution due to improper input validation.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8856 HIGH - 7.7

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8855 HIGH - 8.1

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8854 HIGH - 7.5

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8835 HIGH - 7.3

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8834 HIGH - 8.0

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8620 HIGH - 7.5

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.

Vendor: ibm
Product: websphere_application_server
Published: May 26, 2026
Source: NVD
CVE-2026-7454 HIGH - 7.8

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7452 HIGH - 7.8

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD