Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

894
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 341 - 360 of 27,228 CVEs
CVE-2026-35016 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_query POST parameter directly into an HTML input field VALUE attribute. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35015 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the the_ticket GET parameter directly into a JavaScript variable assignment. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35014 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35013 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values through the thelat and thelng GET parameters directly into JavaScript variable assignments. Atta...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35012 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attack...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35011 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_call GET parameter directly into page output. Attackers can craft a malicious URL co...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35010 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a JavaScript variable assignment. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35009 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35008 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into an HTML attribute. Attackers can craft a maliciou...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35007 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id GET parameter directly into an HTML attribute. Attackers can craft a malicious ...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any authenticat...

Vendor: xwiki
Product: xwiki-platform
Published: May 20, 2026
Source: NVD
CVE-2026-2813 MEDIUM - 4.7

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended, untrusted site, resulting ...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD
CVE-2026-2812 MEDIUM - 5.3

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This is...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD
CVE-2026-26028 MEDIUM - 6.1

CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of <iframe>, <video>, and <audio&...

Vendor: cryptpad
Product: cryptpad
Published: May 20, 2026
Source: NVD
CVE-2026-24218 HIGH - 8.1

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attack...

Vendor: NVIDIA
Product: DGX Spark
Published: May 20, 2026
Source: NVD
CVE-2026-24217 HIGH - 8.8

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-24216 HIGH - 7.8

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-24188 HIGH - 8.2

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.

Vendor: NVIDIA
Product: TensorRT
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnera...

Vendor: xwiki
Product: xwiki-commons
Published: May 20, 2026
Source: NVD
CVE-2026-30691 MEDIUM - 6.1

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode

Published: May 20, 2026
Source: NVD