Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

962
Quick preset (or use dates below)
Clear Filters
Showing 3,021 - 3,040 of 12,982 CVEs
CVE-2026-48896 HIGH - 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48864 HIGH - 7.8

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can le...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, Red Hat Update Infrastructure 4 for Cloud Providers
Published: May 26, 2026
Source: NVD
CVE-2026-48697 HIGH - 7.4

FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but neve...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48690 HIGH - 7.1

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(fastnetmon_pcap_...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48126 HIGH - 8.2

Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the value of the client-s...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD
CVE-2026-44729 HIGH - 8.7

Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authen...

Vendor: twentyhq
Product: twenty
Published: May 26, 2026
Source: NVD
CVE-2026-40384 HIGH - 7.5

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-24212 HIGH - 7.5

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Isaac Launchable
Published: May 26, 2026
Source: NVD
CVE-2026-24162 HIGH - 7.8

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: Merlin Transformers4Rec
Published: May 26, 2026
Source: NVD
CVE-2026-48692 HIGH - 8.1

FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line 477) and a source code comment explicitly acknowledges 'Listen on the given address with...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48688 HIGH - 7.5

FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks to avoid reads ...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-43935 HIGH - 8.1

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. This can lead to phishing attacks, account takeover, or...

Vendor: e107inc
Product: e107
Published: May 26, 2026
Source: NVD
CVE-2026-25112 HIGH - 7.8

A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.

Vendor: Genetec Inc.
Product: Genetec RabbitMQ, Genetec Mission Control, Genetec Sipelia, Genetec Industrial IoT, Genetec Airport Operational Manager, Genetec Restricted Security Area, Genetec Inter-System Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-9552 HIGH - 7.3

A security flaw has been discovered in Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exploit has been releas...

Published: May 26, 2026
Source: NVD
CVE-2026-9551 HIGH - 7.3

A vulnerability was identified in Das Parking Management System ๅœ่ฝฆๅœบ็ฎก็†็ณป็ปŸ 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The manipulation of the argument Value leads to sql injection. It is possible to initiate the attack remo...

Published: May 26, 2026
Source: NVD
CVE-2026-9550 HIGH - 7.3

A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead to path traversal. Th...

Published: May 26, 2026
Source: NVD
CVE-2026-4480 HIGH - 8.5

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this ...

Vendor: redhat
Product: openshift_container_platform
Published: May 26, 2026
Source: NVD
CVE-2026-46368 HIGH - 8.8

luci-app-https-dns-proxy through 2025.12.29-5 โ€” an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default โ€” contains a command injection vulnerability in the setInitAction function. An authenticated user holdi...

Vendor: mossdef-org
Product: luci-app-https-dns-proxy
Published: May 26, 2026
Source: NVD
CVE-2026-45082 HIGH - 7.6

Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward ...

Vendor: karakeep-app
Product: karakeep
Published: May 26, 2026
Source: NVD
CVE-2026-42785 HIGH - 7.2

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands i...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD