Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,428
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,261 - 3,280 of 13,241 CVEs
CVE-2026-42326 MEDIUM - 5.1

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-41949 MEDIUM - 5.9

Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve u...

Vendor: npm
Product: neotoma
Published: May 18, 2026
Source: GitHub
CVE-2026-45626 MEDIUM - 6.3

Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell command (sh -c "find โ€ฆ | while โ€ฆ") inside an Arcane helper container. The...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45620 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenticated user enumeration.

Vendor: composer
Product: WWBN/AVideo
Published: May 18, 2026
Source: GitHub
CVE-2026-45582 MEDIUM - 6.5

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry bac...

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub
CVE-2026-8802 MEDIUM - 4.3

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identifie...

Published: May 18, 2026
Source: NVD
CVE-2026-41119 MEDIUM - 6.8

Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.

Vendor: Dell
Product: Live Optics
Published: May 18, 2026
Source: NVD
CVE-2026-6345 MEDIUM - 6.5

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Advisory ID: MMSA-2026-00614

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-6343 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get.. Mattermost Advisory ID: MMSA-2026-00591

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-6339 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image tag.. Matter...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-5163 MEDIUM - 6.5

Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not have access to via a crafted request to the post rewrite en...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-3471 MEDIUM - 6.5

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Adviso...

Published: May 18, 2026
Source: NVD
CVE-2026-3117 MEDIUM - 6.5

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} c...

Published: May 18, 2026
Source: NVD
CVE-2026-28732 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom sl...

Vendor: Mattermost
Product: Mattermost
Published: May 18, 2026
Source: NVD
CVE-2026-6342 MEDIUM - 4.3

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were not whitelisted via creating groups that share the same prefix as a whitelisted group. Mattermost Advisory ID: MMSA-20...

Published: May 18, 2026
Source: NVD
CVE-2026-6341 MEDIUM - 4.3

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can create issues or attach comments to which allows a user that is member of multiple groups to create issues to a locked group via direct API requests. Mattermost Advisory ID: MMSA...

Published: May 18, 2026
Source: NVD
CVE-2026-6340 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive fol...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-3637 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post ...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-2325 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD