Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,461 - 3,480 of 13,241 CVEs
CVE-2026-44884 MEDIUM - 6.5

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template file endpoint (GET /a...

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44885 MEDIUM - 5.5

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and extracts it to a target...

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-45076 MEDIUM - 2.7

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerabilit...

Vendor: pip
Product: matrix-synapse
Published: May 14, 2026
Source: GitHub
CVE-2026-44722 MEDIUM - 6.2

pyzipper has an encryption bypass for small files encrypted using it

Vendor: pip
Product: pyzipper
Published: May 14, 2026
Source: GitHub
CVE-2026-44501 MEDIUM - 4.3

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization...

Vendor: datahub-project
Product: datahub
Published: May 14, 2026
Source: NVD
CVE-2026-42159 MEDIUM - 5.4

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of...

Vendor: reconurge
Product: flowsint
Published: May 14, 2026
Source: NVD
CVE-2026-42853 MEDIUM - 6.5

ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a command injection vulnerability in the apos create command. User-supplied input from the password prompt is embedded directly into a shell command without...

Vendor: npm
Product: @apostrophecms/cli
Published: May 14, 2026
Source: GitHub
CVE-2026-41933 MEDIUM - 5.3

Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, ...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-41932 MEDIUM - 6.1

Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name field before sanitization occurs. Attackers can submit HTML and script markup in the username field durin...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-24711 MEDIUM - 5.3

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.

Vendor: northern.tech
Product: cfengine
Published: May 14, 2026
Source: NVD
CVE-2026-24710 MEDIUM - 6.1

Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.

Vendor: northern.tech
Product: cfengine
Published: May 14, 2026
Source: NVD
CVE-2025-69443 MEDIUM - 6.3

Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all Archon information available on the UI including API keys.

Published: May 14, 2026
Source: NVD
CVE-2026-6575 MEDIUM - 4.3

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before Postgr...

Vendor: postgresql
Product: postgresql
Published: May 14, 2026
Source: NVD
CVE-2026-6478 MEDIUM - 6.5

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed pas...

Vendor: postgresql
Product: postgresql
Published: May 14, 2026
Source: NVD
CVE-2026-6474 MEDIUM - 4.3

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Vendor: postgresql
Product: postgresql
Published: May 14, 2026
Source: NVD
CVE-2026-6472 MEDIUM - 5.4

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before Postgr...

Vendor: postgresql
Product: postgresql
Published: May 14, 2026
Source: NVD
CVE-2026-46356 MEDIUM - 7.5

Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force login attempts or other abuse against Fleet instances e...

Vendor: go
Product: github.com/fleetdm/fleet
Published: May 14, 2026
Source: GitHub
CVE-2026-26191 MEDIUM - 9.8

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered. Wh...

Vendor: go
Product: github.com/fleetdm/fleet/v4
Published: May 14, 2026
Source: GitHub
CVE-2026-6008 MEDIUM - 6.8

Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.12.1 before v4.5.13.0.

Published: May 14, 2026
Source: NVD
CVE-2026-43644 MEDIUM - 5.4

podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTM...

Vendor: stefanprodan
Product: podinfo
Published: May 14, 2026
Source: NVD