Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,555
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,041 - 3,060 of 28,420 CVEs
CVE-2026-44259 MEDIUM - 4.6

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security headers. Files with .html, .htm, or .svg extensions are served as text/html or image/svg+xml respectively,...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and home containment, but does not validate the dst (destination) parameter used by elfinder_paste. An attacker can copy or move files from within the home di...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and lands anywhere the Tomc...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD
CVE-2026-44015 HIGH - 8.5

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forward...

Vendor: 0xJacky
Product: nginx-ui
Published: May 12, 2026
Source: NVD
CVE-2026-42855 HIGH - 7.5

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp32 computes the authentication hash using the URI field from the client's Authorization header, ...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-42854 CRITICAL - 9.8

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP heade...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-42268 HIGH - 7.5

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @veri...

Vendor: owasp-modsecurity
Product: ModSecurity
Published: May 12, 2026
Source: NVD
CVE-2026-41195 MEDIUM - 5.0

mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker-controlled URL that the server later fetches. Because the server follows http/https redirects and do...

Vendor: mosparo
Product: mosparo
Published: May 12, 2026
Source: NVD
CVE-2026-35555 MEDIUM - 6.3

PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2026-33570 MEDIUM - 5.7

PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020
Published: May 12, 2026
Source: NVD
CVE-2026-26289 HIGH - 8.2

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2026-44403 HIGH - 7.2

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session va...

Vendor: Wing FTP Server
Product: Wing FTP Server
Published: May 12, 2026
Source: NVD
CVE-2026-44246 HIGH - 7.2

nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable to Agentic Workflow Injection. The workflow sets allowed_non_write_users: ${{ github.event.issue.use...

Vendor: MIC-DKFZ
Product: nnUNet
Published: May 12, 2026
Source: NVD
CVE-2026-44224 HIGH - 8.8

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model witho...

Vendor: requarks
Product: wiki
Published: May 12, 2026
Source: NVD
CVE-2026-35504 MEDIUM - 5.5

PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2025-65088 HIGH - 7.8

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.

Vendor: Ashlar-Vellum
Product: Cobalt, Xenon, Argon, Lithium, Cobalt Share
Published: May 12, 2026
Source: NVD
CVE-2025-65087 HIGH - 7.8

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.

Vendor: Ashlar-Vellum
Product: Cobalt, Xenon, Argon, Lithium, Cobalt Share
Published: May 12, 2026
Source: NVD
CVE-2025-65086 HIGH - 7.8

An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary code when a specially crafted VC6 file is being parsed.

Vendor: Ashlar-Vellum
Product: Cobalt, Xenon, Argon, Lithium, Cobalt Share
Published: May 12, 2026
Source: NVD
CVE-2026-8052 MEDIUM - 6.0

HashiCorp Nomadโ€™s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.

Published: May 12, 2026
Source: NVD
CVE-2026-7474 HIGH - 8.8

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Published: May 12, 2026
Source: NVD