Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,568
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,021 - 3,040 of 28,420 CVEs

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metadata of an investigation of another user. This vulnerability is fixed in 1.2.3.

Vendor: reconurge
Product: flowsint
Published: May 12, 2026
Source: NVD

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a map node with a malicious label that contains arbitrary HTML. When the map tab is selected and a map node marker is selecte...

Vendor: reconurge
Product: flowsint
Published: May 12, 2026
Source: NVD

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a node with a malicious type that can escape an existing Cypher query and an adversary can execute an arbitrary Cypher query....

Vendor: reconurge
Product: flowsint
Published: May 12, 2026
Source: NVD
CVE-2026-1250 HIGH - 7.5

The Court Reservation โ€“ Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the โ€˜idโ€™ parameter in all versions up to, and including, 1.10.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...

Published: May 12, 2026
Source: NVD
CVE-2025-15463 MEDIUM - 6.5

The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes ...

Vendor: hwk-fr
Product: Advanced Custom Fields: Extended
Published: May 12, 2026
Source: NVD

UltraJSON has a Memory Leak in ujson.dump() on Write Failure

Vendor: pip
Product: ujson
Published: May 12, 2026
Source: GitHub

SillyTavern has a SSRF vulnerability in the CORS proxy middleware

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub

SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44650 CRITICAL - 9.1

SillyTavern has a Path Traversal issue

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44649 CRITICAL - 9.8

SillyTavern has Authentication Bypass via SSO Header Injection

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44648 HIGH - 7.5

SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44594 HIGH - 7.5

esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: May 12, 2026
Source: GitHub

esm.sh: Legacy Route Path Traversal Can Lead to RCE

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: May 12, 2026
Source: GitHub
CVE-2026-8449 HIGH - 8.8

Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subau...

Published: May 12, 2026
Source: NVD
CVE-2026-45227 HIGH - 8.8

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __impo...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45226 HIGH - 7.1

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds poin...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45225 HIGH - 7.6

Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted filename with traversal sequences. Attackers can exploit the unvalidated filename parameter in the u...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-44871 HIGH - 7.2

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying opera...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-44296 HIGH - 7.5

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and its first bytes do not parse as a valid TLS ClientH...

Vendor: deskflow
Product: deskflow
Published: May 12, 2026
Source: NVD
CVE-2026-44260 HIGH - 8.1

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no event handler c...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD