Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
Showing 3,501 - 3,520 of 13,079 CVEs
CVE-2026-45805 HIGH - 8.8

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

Vendor: npm
Product: @penpot/mcp
Published: May 19, 2026
Source: GitHub
CVE-2026-45799 HIGH - 7.5

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

Vendor: maven
Product: com.squareup.wire:wire-runtime-jvm
Published: May 19, 2026
Source: GitHub
CVE-2026-8073 HIGH - 7.5

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all versions up to, and including, 6.0.6. This makes it p...

Published: May 19, 2026
Source: NVD
CVE-2026-8604 HIGH - 8.8

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-33633 HIGH - 7.5

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a...

Vendor: kovidgoyal
Product: kitty
Published: May 19, 2026
Source: NVD
CVE-2025-61081 HIGH - 7.5

In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is permanently available. The authentication key enables flash to the Electronic Parking Break (EPB) and Supplemental Restoration System (SRS) related ECUs.

Published: May 19, 2026
Source: NVD
CVE-2026-47358 HIGH - 7.5

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates vi...

Vendor: tenable
Product: Terrascan
Published: May 19, 2026
Source: NVD
CVE-2026-47357 HIGH - 7.5

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled ...

Vendor: tenable
Product: Terrascan
Published: May 19, 2026
Source: NVD
CVE-2026-47356 HIGH - 7.5

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_ur...

Vendor: tenable
Product: Terrascan
Published: May 19, 2026
Source: NVD
CVE-2026-36828 HIGH - 8.8

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.

Published: May 19, 2026
Source: NVD
CVE-2026-46426 HIGH - 7.6

Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content restrictions for authenticated users. The checks for dangerous file extensions are conditionally wrapped inside if (isPublicUser) or if (isPublicUser ...

Vendor: npm
Product: budibase
Published: May 19, 2026
Source: GitHub
CVE-2026-45793 HIGH - 7.5

Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs

Vendor: composer
Product: composer/composer
Published: May 19, 2026
Source: GitHub
CVE-2026-5804 HIGH - 8.4

An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing ...

Published: May 19, 2026
Source: NVD
CVE-2026-31069 HIGH - 8.8

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although fi...

Published: May 19, 2026
Source: NVD
CVE-2026-45738 HIGH - 7.3

Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation

Vendor: go
Product: github.com/argoproj/argo-cd/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-45713 HIGH - 7.5

Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes

Vendor: go
Product: github.com/axllent/mailpit
Published: May 19, 2026
Source: GitHub

zrok copy writes attacker-controlled WebDAV paths outside the destination root

Vendor: go
Product: github.com/openziti/zrok/v2
Published: May 19, 2026
Source: GitHub
CVE-2026-8711 HIGH - 8.1

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vuln...

Published: May 19, 2026
Source: NVD
CVE-2026-47100 HIGH - 7.5

Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can injec...

Vendor: FunnelKit
Product: Funnel Builder for WooCommerce Checkout
Published: May 19, 2026
Source: NVD
CVE-2026-43634 HIGH - 7.5

HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's ...

Vendor: hestiacp
Product: hestiacp
Published: May 19, 2026
Source: NVD