Total CVEs

132,371

Critical Severity

2,837

High Severity

10,154

Last 7 Days

1,751
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,281 - 3,300 of 28,776 CVEs
CVE-2026-44796 MEDIUM - 6.5

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44794 MEDIUM - 5.4

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44774 MEDIUM - 9.9

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider a...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: May 13, 2026
Source: GitHub
CVE-2026-44740 MEDIUM - 6.5

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 13, 2026
Source: GitHub
CVE-2026-45134 HIGH - 7.1

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt ma...

Vendor: pip
Product: langsmith
Published: May 13, 2026
Source: GitHub
CVE-2026-44724 HIGH - 7.8

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained int...

Vendor: npm
Product: systeminformation
Published: May 13, 2026
Source: GitHub
CVE-2026-8463 MEDIUM - 5.3

Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without checking that encoded_len is non-zero. When the encoded string is ...

Vendor: leont
Product: crypt\
Published: May 13, 2026
Source: NVD

Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all platforms allows an attacker on the adjacent IPv4 network to inject corrupted IPv6 packets into the Thread mesh or bypass security checks via crafted IPv4 packets with options.

Published: May 13, 2026
Source: NVD
CVE-2026-4609 HIGH - 7.1

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level ...

Published: May 13, 2026
Source: NVD
CVE-2026-4608 MEDIUM - 6.5

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...

Published: May 13, 2026
Source: NVD
CVE-2026-4607 MEDIUM - 4.3

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_i...

Published: May 13, 2026
Source: NVD

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-...

Vendor: mtrudel
Product: bandit
Published: May 13, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1/socket.ex ignores the caller-supplied :length opti...

Vendor: mtrudel
Product: bandit
Published: May 13, 2026
Source: NVD
CVE-2026-37430 HIGH - 7.3

An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.

Published: May 13, 2026
Source: NVD
CVE-2026-37429 MEDIUM - 6.5

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII) via a crafted SQL ...

Published: May 13, 2026
Source: NVD
CVE-2026-37428 MEDIUM - 6.5

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII).

Published: May 13, 2026
Source: NVD
CVE-2026-6177 HIGH - 7.2

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts A...

Published: May 13, 2026
Source: NVD
CVE-2026-42961 MEDIUM - 4.3

ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-42950 MEDIUM - 4.3

ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-42948 MEDIUM - 4.8

Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD