Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,021 - 3,040 of 12,512 CVEs
CVE-2026-41076 HIGH - 8.1

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may ...

Published: May 22, 2026
Source: NVD
CVE-2026-41075 HIGH - 8.8

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them ...

Published: May 22, 2026
Source: NVD
CVE-2026-41074 HIGH - 7.1

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that use...

Published: May 22, 2026
Source: NVD
CVE-2026-41071 HIGH - 8.1

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructo...

Vendor: struktur
Product: libheif
Published: May 22, 2026
Source: NVD
CVE-2026-5843 HIGH - 8.2

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Pyth...

Published: May 22, 2026
Source: NVD
CVE-2026-5817 HIGH - 8.2

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled ...

Published: May 22, 2026
Source: NVD
CVE-2026-9291 HIGH - 7.1

Insecure deserialization in the job results processing component in Amazon Braket SDK beforeΒ 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to ama...

Published: May 22, 2026
Source: NVD
CVE-2026-6406 HIGH - 8.8

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker soc...

Vendor: docker
Product: docker_desktop
Published: May 22, 2026
Source: NVD
CVE-2026-40172 HIGH - 8.1

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, withou...

Published: May 22, 2026
Source: NVD
CVE-2026-39968 HIGH - 7.1

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution and API Authorization Bypass") is incomplete. While the builder's getCredentials tRPC endpoint was patched with workspace membership che...

Published: May 22, 2026
Source: NVD
CVE-2026-46727 HIGH - 8.1

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that c...

Vendor: ruby-lang
Product: ruby
Published: May 22, 2026
Source: NVD
CVE-2026-39965 HIGH - 7.7

TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl() to block private IPs and cloud metadata hostnames. However, the HTTP clients (ky and fetch) follow ...

Published: May 22, 2026
Source: NVD
CVE-2026-9255 HIGH - 7.8

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1...

Published: May 22, 2026
Source: NVD
CVE-2026-37470 HIGH - 7.3

An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components

Published: May 22, 2026
Source: NVD
CVE-2026-36228 HIGH - 7.3

Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality

Published: May 22, 2026
Source: NVD
CVE-2026-34207 HIGH - 7.6

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It does not resolve DNS before allowing the request. As a result, a hostname such as ssrf-repro.example ...

Published: May 22, 2026
Source: NVD
CVE-2026-28445 HIGH - 8.7

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML directive without any sanitization, even though DOMPurify is already a dependency and is used elsewher...

Vendor: npm
Product: @typebot.io/js
Published: May 22, 2026
Source: NVD
CVE-2026-9047 HIGH - 7.6

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * D...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-7325 HIGH - 7.1

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects : ...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2022-31231 HIGH - 7.5

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.

Vendor: dell
Product: elastic_cloud_storage
Published: May 22, 2026
Source: NVD