Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,413
Quick preset (or use dates below)
Clear Filters
Showing 3,581 - 3,600 of 13,622 CVEs
CVE-2026-44796 MEDIUM - 6.5

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to application-wide denial of service via maliciously crafted regular expressions in the find field in co...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44794 MEDIUM - 5.4

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database t...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44774 MEDIUM - 9.9

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider a...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: May 13, 2026
Source: GitHub
CVE-2026-44740 MEDIUM - 6.5

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient v...

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 13, 2026
Source: GitHub
CVE-2026-8463 MEDIUM - 5.3

Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without checking that encoded_len is non-zero. When the encoded string is ...

Vendor: leont
Product: crypt\
Published: May 13, 2026
Source: NVD
CVE-2026-4608 MEDIUM - 6.5

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...

Published: May 13, 2026
Source: NVD
CVE-2026-4607 MEDIUM - 4.3

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_i...

Published: May 13, 2026
Source: NVD
CVE-2026-37429 MEDIUM - 6.5

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII) via a crafted SQL ...

Published: May 13, 2026
Source: NVD
CVE-2026-37428 MEDIUM - 6.5

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII).

Published: May 13, 2026
Source: NVD
CVE-2026-42961 MEDIUM - 4.3

ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-42950 MEDIUM - 4.3

ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-42948 MEDIUM - 4.8

Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-3426 MEDIUM - 4.3

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_widget() and reset_all_widgets() functions in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with Author...

Published: May 13, 2026
Source: NVD
CVE-2026-25107 MEDIUM - 6.5

ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.

Vendor: ELECOM CO.,LTD.
Product: WRC-X1800GS-B, WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B, WRC-X3000GST2-B, WRC-X1800GSA-B, WRC-X1800GSH-B, WRC-X6000QS-G, WRC-X6000QSA-G, WRC-X6000XS-G, WRC-X6000XST-G, WRC-XE5400GS-G, WRC-XE5400GSA-G
Published: May 13, 2026
Source: NVD
CVE-2026-7168 MEDIUM - 5.3

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for...

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-7009 MEDIUM - 5.3

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-6429 MEDIUM - 5.3

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-6253 MEDIUM - 5.9

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while...

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-5545 MEDIUM - 6.5

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid over...

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-4873 MEDIUM - 5.9

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmi...

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD