Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,121 - 3,140 of 12,514 CVEs
CVE-2026-34929 HIGH - 7.8

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different inter-process communication mechanism. Please note: an attacker must first obtain the ability to ex...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-34928 HIGH - 7.8

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different named pipe communication mechanism. Please note: an attacker must first obtain the ability to execu...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-34927 HIGH - 7.8

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-2740 HIGH - 8.4

Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.

Published: May 21, 2026
Source: NVD
CVE-2025-71217 HIGH - 7.8

An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in o...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One (Mac)
Published: May 21, 2026
Source: NVD
CVE-2025-71216 HIGH - 7.8

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to e...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One (Mac)
Published: May 21, 2026
Source: NVD
CVE-2025-71215 HIGH - 7.0

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One (Mac)
Published: May 21, 2026
Source: NVD
CVE-2025-71214 HIGH - 7.8

An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to expl...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One (Mac)
Published: May 21, 2026
Source: NVD
CVE-2025-71213 HIGH - 7.8

An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2025-71212 HIGH - 7.8

A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2025-13479 HIGH - 7.5

Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers. This issue affects QR Menu: through 21052026.ย NOTE: The vendor was contacted early about this disclosure but did not respond in any way...

Vendor: PosCube Hardware Software and Consulting Ltd.
Product: QR Menu
Published: May 21, 2026
Source: NVD
CVE-2025-13477 HIGH - 7.1

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026.ย NOTE: The vendor was contacted early about this disclos...

Vendor: Digital Operations Services Inc.
Product: WifiBurada
Published: May 21, 2026
Source: NVD
CVE-2026-45760 HIGH - 8.1

(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the ...

Vendor: Apache Software Foundation
Product: Apache Camel K
Published: May 21, 2026
Source: NVD
CVE-2026-45255 HIGH - 7.5

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the user to select a network. This is implemented using a shell script, and the code which handled network names was not careful to prevent expansion by ...

Vendor: FreeBSD
Product: FreeBSD
Published: May 21, 2026
Source: NVD
CVE-2026-45252 HIGH - 7.5

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. The fusefs kernel mo...

Vendor: FreeBSD
Product: FreeBSD
Published: May 21, 2026
Source: NVD
CVE-2026-45251 HIGH - 7.8

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread does not hold a reference to the underlying object, this closure may result in the object being freed while the thread remains blocked. In this situation...

Vendor: FreeBSD
Product: FreeBSD
Published: May 21, 2026
Source: NVD
CVE-2026-42001 HIGH - 7.5

Insufficient Validation of Autoprimary SOA Queries

Vendor: PowerDNS
Product: Authoritative
Published: May 21, 2026
Source: NVD
CVE-2026-28764 HIGH - 7.8

MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 21, 2026
Source: NVD
CVE-2026-9157 HIGH - 8.4

Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issue affects Web Fax: from 3.0 before 3.1.

Published: May 21, 2026
Source: NVD
CVE-2026-4858 HIGH - 8.0

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integra...

Vendor: mattermost
Product: mattermost_server
Published: May 21, 2026
Source: NVD