Total CVEs

138,500

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,016
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,441 - 3,460 of 12,518 CVEs
CVE-2026-45062 HIGH - 8.1

FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Fran...

Vendor: go
Product: github.com/dunglas/frankenphp
Published: May 15, 2026
Source: GitHub
CVE-2026-44716 HIGH - 7.5

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal vulnerability exists in Pipecat's development runner (src/pipecat/runner/run.py). When the runner is started with the --fol...

Vendor: pip
Product: pipecat-ai
Published: May 15, 2026
Source: GitHub
CVE-2026-41147 HIGH - 8.7

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies primarily on client-side filtering to sanitize HTML tags and attri...

Vendor: composer
Product: nukeviet/nukeviet
Published: May 15, 2026
Source: GitHub
CVE-2026-40092 HIGH - 7.5

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, Ke...

Vendor: rust
Product: nimiq-keys
Published: May 15, 2026
Source: GitHub
CVE-2026-22810 HIGH - 8.2

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded fil...

Vendor: npm
Product: @joplin/onenote-converter
Published: May 15, 2026
Source: GitHub
CVE-2026-46508 HIGH - 7.8

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and tas...

Vendor: vercel
Product: turborepo
Published: May 15, 2026
Source: NVD
CVE-2026-35194 HIGH - 8.1

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE exp...

Vendor: Apache Software Foundation
Product: Apache Flink
Published: May 15, 2026
Source: NVD
CVE-2026-39054 HIGH - 7.3

Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operati...

Published: May 15, 2026
Source: NVD
CVE-2026-38728 HIGH - 7.5

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components

Published: May 15, 2026
Source: NVD
CVE-2026-34253 HIGH - 8.2

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause appli...

Published: May 15, 2026
Source: NVD
CVE-2026-41552 HIGH - 7.5

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed ...

Vendor: DHTMLX
Product: PDF Export Module
Published: May 15, 2026
Source: NVD
CVE-2026-41964 HIGH - 8.4

Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

Vendor: Huawei
Product: HarmonyOS
Published: May 15, 2026
Source: NVD
CVE-2026-6403 HIGH - 7.5

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path ...

Published: May 15, 2026
Source: NVD
CVE-2026-6228 HIGH - 8.8

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admi...

Published: May 15, 2026
Source: NVD
CVE-2026-4094 HIGH - 8.1

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contrib...

Published: May 15, 2026
Source: NVD
CVE-2026-41702 HIGH - 7.8

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installe...

Vendor: VMware
Product: Fusion
Published: May 15, 2026
Source: NVD
CVE-2026-43490 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify th...

Vendor: Linux
Product: Linux
Published: May 15, 2026
Source: NVD
CVE-2026-28761 HIGH - 8.1

Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.

Vendor: Fujitsu Japan Limited
Product: Musetheque V4 Information Disclosure for IPKNOWLEDGE
Published: May 15, 2026
Source: NVD
CVE-2024-36333 HIGH - 7.8

A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

Vendor: amd
Product: radeon_software
Published: May 15, 2026
Source: NVD
CVE-2026-2652 HIGH - 8.6

A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gate...

Vendor: lfprojects
Product: mlflow
Published: May 15, 2026
Source: NVD