Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,984
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,321 - 3,340 of 12,514 CVEs
CVE-2026-42306 HIGH - 7.2

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary ho...

Vendor: go
Product: github.com/docker/docker
Published: May 18, 2026
Source: GitHub

CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve ...

Vendor: pip
Product: cloakbrowser
Published: May 18, 2026
Source: GitHub
CVE-2026-41567 HIGH - 7.2

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `un...

Vendor: go
Product: github.com/moby/moby/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45716 HIGH - 8.8

Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), ...

Vendor: npm
Product: @budibase/worker
Published: May 18, 2026
Source: GitHub
CVE-2026-45707 HIGH - 8.1

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the target n8n instance is selected per-request from x-n8n-url / x-n8n-key headers. Requests that omitt...

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub
CVE-2026-45363 HIGH - 7.4

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

Vendor: rubygems
Product: jwt
Published: May 18, 2026
Source: GitHub
CVE-2026-45327 HIGH - 8.2

TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the issue by requiring either HTTP Basic auth or a `?password=` query parameter, comparing the supplied p...

Vendor: go
Product: github.com/DatanoiseTV/tinyice
Published: May 18, 2026
Source: GitHub
CVE-2026-41085 HIGH - 8.8

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces.

Published: May 18, 2026
Source: NVD
CVE-2026-45325 HIGH - 8.2

@tmlmobilidade/utils has prototype pollution in its setValueAtPath

Vendor: npm
Product: @tmlmobilidade/utils
Published: May 18, 2026
Source: GitHub
CVE-2026-45302 HIGH - 8.2

parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with ...

Vendor: npm
Product: parse-nested-form-data
Published: May 18, 2026
Source: GitHub
CVE-2026-45300 HIGH - 7.4

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a d...

Vendor: maven
Product: org.asynchttpclient:async-http-client
Published: May 18, 2026
Source: GitHub
CVE-2026-45298 HIGH - 8.6

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that ...

Vendor: go
Product: github.com/amir20/dozzle
Published: May 18, 2026
Source: GitHub
CVE-2026-46385 HIGH - 7.5

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd6...

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45270 HIGH - 8.7

CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-46384 HIGH - 7.5

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before bounds-checking, or summed them with overflow-prone signed-int arithmetic. On 32-bit targets (GOARCH=...

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2025-57282 HIGH - 8.8

ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.

Published: May 18, 2026
Source: NVD
CVE-2025-56352 HIGH - 7.5

In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length Client ID while CleanSession is set to 0, the broker correctly replies with a CONNACK return code 0x02...

Published: May 18, 2026
Source: NVD
CVE-2026-41948 HIGH - 7.7

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unenc...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-41947 HIGH - 7.4

Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-39079 HIGH - 7.5

An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components

Published: May 18, 2026
Source: NVD