Total CVEs

133,059

Critical Severity

2,915

High Severity

10,581

Last 7 Days

2,052
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,081 - 3,100 of 29,464 CVEs
CVE-2026-45660 MEDIUM - 5.4

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the server to make ...

Vendor: composer
Product: statamic/cms
Published: May 18, 2026
Source: GitHub
CVE-2026-42326 MEDIUM - 5.1

ImageMagick: Heap Buffer Over-Read in IPTC encoder

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-41949 MEDIUM - 5.9

Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-41948 HIGH - 7.7

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unenc...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-41947 HIGH - 7.4

Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-39079 HIGH - 7.5

An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components

Published: May 18, 2026
Source: NVD
CVE-2026-26462 HIGH - 7.3

Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary o...

Published: May 18, 2026
Source: NVD

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object (rather than a String) to Faraday::Connection#build_exclusive_url. This...

Vendor: rubygems
Product: faraday
Published: May 18, 2026
Source: GitHub

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve u...

Vendor: npm
Product: neotoma
Published: May 18, 2026
Source: GitHub
CVE-2026-45627 HIGH - 8.2

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45626 MEDIUM - 6.3

Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell command (sh -c "find โ€ฆ | while โ€ฆ") inside an Arcane helper container. The...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45625 CRITICAL - 9.9

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials. E...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45135 HIGH - 8.1

Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45620 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenticated user enumeration.

Vendor: composer
Product: WWBN/AVideo
Published: May 18, 2026
Source: GitHub
CVE-2026-45609 HIGH - 7.2

mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted UR...

Vendor: maven
Product: org.springaicommunity:mcp-client-security
Published: May 18, 2026
Source: GitHub
CVE-2026-46510 HIGH - 8.2

form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose name starts with __proto__[...] causes the library to mu...

Vendor: npm
Product: form-data-objectizer
Published: May 18, 2026
Source: GitHub
CVE-2026-45582 MEDIUM - 6.5

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry bac...

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub
CVE-2026-42009 HIGH - 7.5

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This cou...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 18, 2026
Source: NVD
CVE-2026-8803 LOW - 3.7

A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have...

Published: May 18, 2026
Source: NVD
CVE-2026-7304 CRITICAL - 9.8

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD