Total CVEs

133,071

Critical Severity

2,915

High Severity

10,590

Last 7 Days

2,060
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,321 - 3,340 of 29,476 CVEs
CVE-2026-45717 HIGH - 8.8

Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the same authorization level as the read endpoint (GET /a...

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45715 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated Builder to access internal services (cloud metadata, databases) by redirect...

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45548 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all other automation steps. This allows an authenticated ...

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45364 HIGH - 7.3

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients controlling a typica...

Vendor: npm
Product: better-auth
Published: May 15, 2026
Source: GitHub
CVE-2026-8695 HIGH - 7.5

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debu...

Vendor: radare
Product: radare2
Published: May 15, 2026
Source: NVD
CVE-2026-46383 MEDIUM - 5.5

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm instal...

Vendor: microsoft
Product: apm
Published: May 15, 2026
Source: NVD
CVE-2026-45539 HIGH - 7.4

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rglob() calls and read each match with Path.read_text(), transparently following symbolic links. A symli...

Vendor: microsoft
Product: apm
Published: May 15, 2026
Source: NVD
CVE-2026-45038 HIGH - 7.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45037 HIGH - 7.1

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafte...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45036 HIGH - 7.0

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatically confirms ZMODEM protocol detection on all terminal session output without user interaction, enabling shell command execution when a user displays attacker-controlled content. Th...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45035 HIGH - 8.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or san...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-44717 CRITICAL - 9.8

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.

Vendor: 611711Dark
Product: mcp_calculate_server
Published: May 15, 2026
Source: NVD

LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes HMAC verification to run with a zero-length key, so an attacker can forge a valid JW...

Vendor: benmcollins
Product: libjwt
Published: May 15, 2026
Source: NVD
CVE-2026-23695 MEDIUM - 5.4

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html direct...

Vendor: Cockpit-HQ
Product: Cockpit
Published: May 15, 2026
Source: NVD
CVE-2026-45106 MEDIUM - 4.6

Weblate: Stored HTML injection in editor search preview

Vendor: pip
Product: weblate
Published: May 15, 2026
Source: GitHub
CVE-2026-45062 HIGH - 8.1

FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files

Vendor: go
Product: github.com/dunglas/frankenphp
Published: May 15, 2026
Source: GitHub
CVE-2026-44716 HIGH - 7.5

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint โ€” Arbitrary File Read via `%2F`-Encoded Separator

Vendor: pip
Product: pipecat-ai
Published: May 15, 2026
Source: GitHub
CVE-2026-41147 HIGH - 8.7

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies primarily on client-side filtering to sanitize HTML tags and attri...

Vendor: composer
Product: nukeviet/nukeviet
Published: May 15, 2026
Source: GitHub
CVE-2026-40092 HIGH - 7.5

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, Ke...

Vendor: rust
Product: nimiq-keys
Published: May 15, 2026
Source: GitHub
CVE-2026-22810 HIGH - 8.2

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded fil...

Vendor: npm
Product: @joplin/onenote-converter
Published: May 15, 2026
Source: GitHub