Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
Showing 3,001 - 3,020 of 12,982 CVEs
CVE-2026-7451 HIGH - 7.8

A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-48695 HIGH - 8.1

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() c...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48694 HIGH - 8.1

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is directly interpolated into Juniper NETCONF set-configuration commands...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-44730 HIGH - 7.2

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their own organization. This is due to incorrect ACL on u...

Vendor: OpenCTI-Platform
Product: opencti
Published: May 26, 2026
Source: NVD
CVE-2026-44706 HIGH - 8.5

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type date or number using the is_greater_than or is_less_than operators, user-supplied values in the values ...

Vendor: chatwoot
Product: chatwoot
Published: May 26, 2026
Source: NVD
CVE-2026-44669 HIGH - 8.7

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts wit...

Vendor: factionsecurity
Product: faction
Published: May 26, 2026
Source: NVD
CVE-2026-44667 HIGH - 8.7

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification file preview flows. User-supplied filename values are persisted and then rendered into HTML and attri...

Vendor: factionsecurity
Product: faction
Published: May 26, 2026
Source: NVD
CVE-2026-24200 HIGH - 7.0

NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24196 HIGH - 7.1

NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver
Published: May 26, 2026
Source: NVD
CVE-2026-24195 HIGH - 7.1

NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Guest driver
Published: May 26, 2026
Source: NVD
CVE-2026-24194 HIGH - 7.8

NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execu...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver
Published: May 26, 2026
Source: NVD
CVE-2026-24193 HIGH - 7.8

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla
Published: May 26, 2026
Source: NVD
CVE-2026-24192 HIGH - 7.8

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data ...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24191 HIGH - 7.8

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-24190 HIGH - 7.8

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and ...

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla
Published: May 26, 2026
Source: NVD
CVE-2026-24187 HIGH - 8.8

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor: NVIDIA
Product: GeForce, RTX, Quadro, NVS, Tesla, Guest driver, Virtual GPU Manager
Published: May 26, 2026
Source: NVD
CVE-2026-9562 HIGH - 7.3

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been...

Published: May 26, 2026
Source: NVD
CVE-2026-8850 HIGH - 7.5

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-48901 HIGH - 7.5

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48897 HIGH - 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD