Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,981 - 3,000 of 13,146 CVEs
CVE-2026-44390 MEDIUM - 5.3

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound ...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-42923 MEDIUM - 5.3

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the att...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-42534 MEDIUM - 5.3

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential t...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-35070 MEDIUM - 6.4

Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access...

Vendor: Dell
Product: SmartFabric Storage Software
Published: May 20, 2026
Source: NVD
CVE-2026-32792 MEDIUM - 5.3

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious act...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-6405 MEDIUM - 4.3

The Anomify AI โ€“ Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in versions up to and including 0.3.6. This is due to missing nonce verification on the settings page handler and insufficient output e...

Published: May 20, 2026
Source: NVD
CVE-2026-7385 MEDIUM - 5.8

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email addresses.

Published: May 20, 2026
Source: NVD
CVE-2026-6566 MEDIUM - 4.3

The Photo Gallery, Sliders, Proofing and Themes โ€“ NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DEL...

Published: May 20, 2026
Source: NVD
CVE-2026-5776 MEDIUM - 6.1

The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks

Published: May 20, 2026
Source: NVD
CVE-2026-44392 MEDIUM - 4.3

Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.

Vendor: Six Apart Ltd.
Product: Movable Type, Movable Type Advanced, Movable Type Premium, Movable Type Premium (Advanced Edition)
Published: May 20, 2026
Source: NVD
CVE-2026-2955 MEDIUM - 6.4

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate...

Published: May 20, 2026
Source: NVD
CVE-2026-9056 MEDIUM - 5.4

A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be triggered by a different user.

Published: May 20, 2026
Source: NVD
CVE-2026-5075 MEDIUM - 4.3

The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being passed to wp_localize_script() in post editor contexts without effective m...

Published: May 20, 2026
Source: NVD
CVE-2026-24215 MEDIUM - 5.7

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24208 MEDIUM - 5.3

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24160 MEDIUM - 5.5

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: TensorRT-LLM
Published: May 20, 2026
Source: NVD
CVE-2026-24142 MEDIUM - 6.3

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: TensorRT-LLM
Published: May 20, 2026
Source: NVD
CVE-2025-15369 MEDIUM - 5.3

The Xpro Addons โ€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create publis...

Vendor: xpro
Product: Xpro Addons โ€” 140+ Widgets for Elementor
Published: May 20, 2026
Source: NVD
CVE-2026-8685 MEDIUM - 6.5

The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL ...

Published: May 20, 2026
Source: NVD
CVE-2026-8627 MEDIUM - 6.1

The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is due to the correct_prices_page() function echoing $_SERVER['PHP_SELF'] into a form's action attribute wi...

Published: May 20, 2026
Source: NVD