Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,041 - 3,060 of 12,512 CVEs
CVE-2026-9256 HIGH - 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that re...

Published: May 22, 2026
Source: NVD
CVE-2026-8992 HIGH - 8.8

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

Vendor: ivanti
Product: secure_access_client
Published: May 22, 2026
Source: NVD
CVE-2025-45145 HIGH - 7.5

Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter

Published: May 22, 2026
Source: NVD
CVE-2026-9277 HIGH - 8.1

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.o...

Vendor: npm
Product: shell-quote
Published: May 22, 2026
Source: NVD
CVE-2026-8671 HIGH - 7.5

Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2025-32749 HIGH - 7.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-32747 HIGH - 7.8

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-26483 HIGH - 8.2

Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to con...

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2026-44417 HIGH - 7.5

The fix forΒ CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, ...

Vendor: apache
Product: cxf
Published: May 22, 2026
Source: NVD
CVE-2026-5740 HIGH - 7.5

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server process and cause a full service outage fo...

Vendor: mattermost
Product: mattermost_server
Published: May 22, 2026
Source: NVD
CVE-2026-5308 HIGH - 7.5

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTTP requests.. Mattermost Advisory ID: MMSA-2026-00...

Vendor: mattermost
Product: mattermost_server
Published: May 22, 2026
Source: NVD
CVE-2026-3473 HIGH - 7.1

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid ...

Vendor: mattermost
Product: mattermost_server
Published: May 22, 2026
Source: NVD
CVE-2026-9011 HIGH - 7.5

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated...

Published: May 22, 2026
Source: NVD
CVE-2026-8679 HIGH - 7.5

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or ...

Published: May 22, 2026
Source: NVD
CVE-2026-9018 HIGH - 8.8

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-co...

Published: May 22, 2026
Source: NVD
CVE-2026-4834 HIGH - 7.5

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published: May 22, 2026
Source: NVD
CVE-2026-46597 HIGH - 7.5

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

Vendor: golang.org/x/crypto
Product: golang.org/x/crypto/ssh
Published: May 22, 2026
Source: NVD
CVE-2026-39829 HIGH - 7.5

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key...

Vendor: golang.org/x/crypto
Product: golang.org/x/crypto/ssh
Published: May 22, 2026
Source: NVD
CVE-2026-34911 HIGH - 7.7

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.

Published: May 22, 2026
Source: NVD
CVE-2026-46701 HIGH - 7.6

Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

Vendor: npm
Product: network-ai
Published: May 21, 2026
Source: GitHub