Total CVEs

138,500

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,017
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,421 - 3,440 of 12,518 CVEs
CVE-2021-47966 HIGH - 8.2

PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database contents. Attackers can submit crafted POST requests with SQL payloads using SLEEP functions or RLIKE cond...

Vendor: Timeclock
Product: PHP Timeclock
Published: May 15, 2026
Source: NVD
CVE-2021-47964 HIGH - 8.8

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the packageinfo.inc file and trigger...

Vendor: Schlix
Product: Schlix CMS
Published: May 15, 2026
Source: NVD
CVE-2021-47963 HIGH - 7.2

Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by injecting malicious payloads into markdown files stored within the application. Attackers can craft malicious markdown files with embedded JavaScript that executes system commands wh...

Vendor: AnotherNote
Product: Anote
Published: May 15, 2026
Source: NVD
CVE-2021-47959 HIGH - 7.5

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads ...

Vendor: Wpgraphql
Product: WPGraphQL
Published: May 15, 2026
Source: NVD
CVE-2026-45578 HIGH - 8.8

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never calling escapeshella...

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45575 HIGH - 7.4

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri...

Vendor: maven
Product: com.oviva.telematik:epa4all-client
Published: May 15, 2026
Source: GitHub
CVE-2026-45574 HIGH - 8.1

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient ide...

Vendor: maven
Product: com.oviva.telematik:epa4all-client
Published: May 15, 2026
Source: GitHub
CVE-2026-46474 HIGH - 7.5

Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Vendor: TEODESIAN
Product: Trog::TOTP
Published: May 15, 2026
Source: NVD
CVE-2026-46491 HIGH - 8.6

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ...

Vendor: composer
Product: simplesamlphp/simplesamlphp-module-casserver
Published: May 15, 2026
Source: GitHub
CVE-2026-44692 HIGH - 7.7

Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity instance, but then reads the target storage disk and path from request parameters. Because the requested...

Vendor: composer
Product: code16/sharp
Published: May 15, 2026
Source: GitHub
CVE-2026-45717 HIGH - 8.8

Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the same authorization level as the read endpoint (GET /a...

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45715 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/integrations/rest.ts) follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated Builder to access internal services (cloud metadata, databases) by redirect...

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45548 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all other automation steps. This allows an authenticated ...

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45364 HIGH - 7.3

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients controlling a typica...

Vendor: npm
Product: better-auth
Published: May 15, 2026
Source: GitHub
CVE-2026-8695 HIGH - 7.5

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debu...

Vendor: radare
Product: radare2
Published: May 15, 2026
Source: NVD
CVE-2026-45539 HIGH - 7.4

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rglob() calls and read each match with Path.read_text(), transparently following symbolic links. A symli...

Vendor: microsoft
Product: apm
Published: May 15, 2026
Source: NVD
CVE-2026-45038 HIGH - 7.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45037 HIGH - 7.1

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafte...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45036 HIGH - 7.0

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatically confirms ZMODEM protocol detection on all terminal session output without user interaction, enabling shell command execution when a user displays attacker-controlled content. Th...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45035 HIGH - 8.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or san...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD