Total CVEs

132,167

Critical Severity

2,835

High Severity

10,137

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,461 - 3,480 of 28,572 CVEs
CVE-2026-31230 CRITICAL - 9.8

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the unsafe eval() function to parse string values provided via the --clip_values and --input_shape command-...

Published: May 12, 2026
Source: NVD
CVE-2026-31229 CRITICAL - 9.8

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., model.pt) during robustness evaluation, the code uses torch.load() without the...

Published: May 12, 2026
Source: NVD
CVE-2026-29204 CRITICAL - 10.0

Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's resources and their cPanel account.

Vendor: WebPros
Product: WHMCS
Published: May 12, 2026
Source: NVD
CVE-2026-26083 CRITICAL - 9.8

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all vers...

Vendor: Fortinet
Product: FortiSandbox Cloud, FortiSandbox, FortiSandbox PaaS
Published: May 12, 2026
Source: NVD
CVE-2026-25690 MEDIUM - 4.3

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow ...

Vendor: Fortinet
Product: FortiDeceptor
Published: May 12, 2026
Source: NVD
CVE-2026-25088 MEDIUM - 5.4

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions may allow an authenticated attacker ...

Vendor: Fortinet
Product: FortiNDR
Published: May 12, 2026
Source: NVD
CVE-2026-21530 MEDIUM - 6.7

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2026-20767 HIGH - 7.8

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege....

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2026-20714 HIGH - 7.8

Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This r...

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2025-67604 MEDIUM - 5.3

A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, ...

Vendor: Fortinet
Product: FortiAnalyzer, FortiManager
Published: May 12, 2026
Source: NVD
CVE-2025-53870 MEDIUM - 6.7

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, Fo...

Vendor: Fortinet
Product: FortiAP, FortiAP-W2
Published: May 12, 2026
Source: NVD
CVE-2025-53844 HIGH - 8.8

A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.

Vendor: Fortinet
Product: FortiOS
Published: May 12, 2026
Source: NVD
CVE-2025-53681 HIGH - 7.2

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute u...

Vendor: Fortinet
Product: FortiMail
Published: May 12, 2026
Source: NVD
CVE-2025-53680 MEDIUM - 6.7

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-U 7...

Vendor: Fortinet
Product: FortiAP, FortiAP-W2, FortiAP-U
Published: May 12, 2026
Source: NVD
CVE-2025-46311 HIGH - 7.5

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.

Vendor: Apple
Product: iOS and iPadOS
Published: May 12, 2026
Source: NVD
CVE-2025-43524 HIGH - 8.8

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS Sequoia, macOS Sonoma, macOS Tahoe
Published: May 12, 2026
Source: NVD
CVE-2026-8407 MEDIUM - 4.3

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Serve...

Published: May 12, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 12, 2026
Source: NVD
CVE-2026-5089 HIGH - 7.3

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a colon-separated value (e.g., the 1 in 1:30:45), the inner whil...

Published: May 12, 2026
Source: NVD
CVE-2026-43993 HIGH - 8.2

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, resulting in an SSRF vulnerability. This vulnerability is fixed in 0.x.y-security-1.

Vendor: Dragonmonk111
Product: junoclaw
Published: May 12, 2026
Source: NVD