Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,149
Quick preset (or use dates below)
Clear Filters
Showing 3,021 - 3,040 of 13,527 CVEs
CVE-2026-6391 MEDIUM - 6.1

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the create_admin_page() function. This makes it possible for unauthenticated attack...

Published: May 20, 2026
Source: NVD
CVE-2026-6072 MEDIUM - 6.5

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.4.2.6. The plugin protects its entire /wp-json/pos-bridge/* REST API namespace through the oliver_pos_rest_authentication() ...

Published: May 20, 2026
Source: NVD
CVE-2026-5293 MEDIUM - 6.4

The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This is due to missing authorization checks and insufficient input sanitization in the themeFunc() function. The functi...

Published: May 20, 2026
Source: NVD
CVE-2026-43620 MEDIUM - 6.5

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a sp...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-43619 MEDIUM - 6.3

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attacke...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-43617 MEDIUM - 4.8

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connec...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-45585 MEDIUM - 6.8

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance ...

Vendor: microsoft
Product: windows_11_24h2
Published: May 20, 2026
Source: NVD
CVE-2026-39309 MEDIUM - 5.5

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission promp...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-35593 MEDIUM - 6.8

Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read sensitive arbitrary files from the server's filesystem....

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-8493 MEDIUM - 5.4

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS). This issue affects Colorbox Inline: from 0.0.0 before 2.1.1.

Published: May 19, 2026
Source: NVD
CVE-2026-6871 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS). This issue affects Obfuscate: from 0.0.0 before 2.0.2.

Vendor: obfuscate_project
Product: obfuscate
Published: May 19, 2026
Source: NVD
CVE-2026-6367 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6366 MEDIUM - 6.6

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6365 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 1...

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6095 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS). This issue affects Orejime: from 0.0.0 before 2.0.16.

Vendor: gaya
Product: orejime
Published: May 19, 2026
Source: NVD
CVE-2026-34600 MEDIUM - 5.7

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully fixed by the prior pa...

Vendor: laurent22
Product: joplin
Published: May 19, 2026
Source: NVD
CVE-2026-5090 MEDIUM - 6.1

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' t...

Published: May 19, 2026
Source: NVD
CVE-2026-34246 MEDIUM - 4.8

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In app/Http/Controllers/Admin/RoleController.php, the datatable() method interpolates $role->name and ...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2025-15645 MEDIUM - 4.6

Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-control...

Vendor: Ledger
Product: Ledger Nano X, Ledger Flex, Ledger Stax
Published: May 19, 2026
Source: NVD
CVE-2023-7345 MEDIUM - 6.5

Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtai...

Published: May 19, 2026
Source: NVD