Total CVEs

131,648

Critical Severity

2,801

High Severity

10,044

Last 7 Days

1,211
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,021 - 3,040 of 28,053 CVEs
CVE-2026-42073 MEDIUM - 6.5

OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS

Vendor: npm
Product: @gitlawb/openclaude
Published: May 12, 2026
Source: GitHub
CVE-2026-8401 CRITICAL - 9.8

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 12, 2026
Source: NVD
CVE-2026-8368 MEDIUM - 6.5

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent...

Published: May 12, 2026
Source: NVD
CVE-2026-8111 HIGH - 8.8

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

Vendor: ivanti
Product: endpoint_manager
Published: May 12, 2026
Source: NVD
CVE-2026-8110 HIGH - 7.8

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

Vendor: ivanti
Product: endpoint_manager
Published: May 12, 2026
Source: NVD
CVE-2026-8109 MEDIUM - 6.5

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

Vendor: ivanti
Product: endpoint_manager
Published: May 12, 2026
Source: NVD
CVE-2026-8051 HIGH - 7.2

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendor: ivanti
Product: virtual_traffic_manager
Published: May 12, 2026
Source: NVD
CVE-2026-8043 CRITICAL - 9.6

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.

Vendor: ivanti
Product: xtraction
Published: May 12, 2026
Source: NVD
CVE-2026-7432 HIGH - 7.8

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

Vendor: ivanti
Product: secure_access_client
Published: May 12, 2026
Source: NVD
CVE-2026-7431 MEDIUM - 4.4

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.

Vendor: ivanti
Product: secure_access_client
Published: May 12, 2026
Source: NVD

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.

Published: May 12, 2026
Source: NVD
CVE-2026-5061 MEDIUM - 4.7

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.

Published: May 12, 2026
Source: NVD
CVE-2026-43983 HIGH - 8.1

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization s...

Vendor: pocket-id
Product: pocket-id
Published: May 12, 2026
Source: NVD

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifications' module) allows SQL Injection. The channel argument passed to 'Elixir.Postgrex.Notifications':listen/3 and 'E...

Vendor: elixir-ecto
Product: postgrex
Published: May 12, 2026
Source: NVD
CVE-2025-70842 MEDIUM - 5.4

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containing malicious JavaScript code. Once uploaded, the script executes in the browser of any user who access...

Published: May 12, 2026
Source: NVD
CVE-2026-45090 HIGH - 7.5

Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)

Vendor: go
Product: github.com/hahwul/dalfox/v2
Published: May 12, 2026
Source: GitHub
CVE-2026-45089 HIGH - 8.2

Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option

Vendor: go
Product: github.com/hahwul/dalfox/v2
Published: May 12, 2026
Source: GitHub
CVE-2026-45088 HIGH - 7.5

Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`

Vendor: go
Product: github.com/hahwul/dalfox/v2
Published: May 12, 2026
Source: GitHub
CVE-2026-45087 CRITICAL - 10.0

Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`

Vendor: go
Product: github.com/hahwul/dalfox/v2
Published: May 12, 2026
Source: GitHub
CVE-2026-44295 HIGH - 8.7

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service...

Vendor: npm
Product: protobufjs-cli
Published: May 12, 2026
Source: GitHub