Total CVEs

139,258

Critical Severity

3,630

High Severity

13,017

Last 7 Days

1,248
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,141 - 3,160 of 13,208 CVEs
CVE-2026-8957 MEDIUM - 6.5

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8955 MEDIUM - 6.5

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8952 MEDIUM - 6.5

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-8951 MEDIUM - 6.5

Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.

Vendor: mozilla
Product: firefox
Published: May 19, 2026
Source: NVD
CVE-2026-23557 MEDIUM - 6.5

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will happen, as assert() is doing nothing in this case. Note that the default is not to define NDEBUG for xen...

Vendor: Xen
Product: Xen
Published: May 19, 2026
Source: NVD
CVE-2025-40904 MEDIUM - 6.5

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote ...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40903 MEDIUM - 5.9

A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected sch...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40902 MEDIUM - 5.9

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing th...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40901 MEDIUM - 5.9

A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected ide...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2025-40900 MEDIUM - 4.6

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to impor...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: May 19, 2026
Source: NVD
CVE-2026-4630 MEDIUM - 6.8

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same ...

Published: May 19, 2026
Source: NVD
CVE-2026-45442 MEDIUM - 4.3

Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3.

Vendor: Brainstorm Force
Product: Presto Player
Published: May 19, 2026
Source: NVD
CVE-2026-37982 MEDIUM - 6.8

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD
CVE-2026-37981 MEDIUM - 4.3

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By s...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD
CVE-2026-37979 MEDIUM - 6.5

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for ot...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD
CVE-2026-37978 MEDIUM - 4.9

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable informati...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD
CVE-2026-45187 MEDIUM - 6.5

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-35086 MEDIUM - 6.5

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31906 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31388 MEDIUM - 5.3

Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD