Total CVEs

132,451

Critical Severity

2,845

High Severity

10,187

Last 7 Days

1,729
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,581 - 3,600 of 28,856 CVEs
CVE-2026-44279 MEDIUM - 5.5

A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to improper access control via <insert attack vector here>

Vendor: Fortinet
Product: FortiTokenAndroid
Published: May 12, 2026
Source: NVD

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

Vendor: Fortinet
Product: FortiClientWindows
Published: May 12, 2026
Source: NVD
CVE-2026-44277 CRITICAL - 9.8

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Vendor: Fortinet
Product: FortiAuthenticator
Published: May 12, 2026
Source: NVD
CVE-2026-44204 MEDIUM - 6.5

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role) to execute arbitrary SQL and read data from any table in the database, including data belonging to o...

Vendor: Shelf-nu
Product: shelf.nu
Published: May 12, 2026
Source: NVD
CVE-2026-44196 CRITICAL - 9.1

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker ...

Vendor: smp46
Product: pingvin-share-x
Published: May 12, 2026
Source: NVD
CVE-2026-44184 HIGH - 8.0

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddre...

Vendor: Cleanuparr
Product: Cleanuparr
Published: May 12, 2026
Source: NVD
CVE-2026-44183 CRITICAL - 9.8

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the client IP. That entry ...

Vendor: Cleanuparr
Product: Cleanuparr
Published: May 12, 2026
Source: NVD
CVE-2026-43892 HIGH - 8.8

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16.

Vendor: AntSwordProject
Product: antSword
Published: May 12, 2026
Source: NVD
CVE-2026-42899 HIGH - 7.5

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Vendor: microsoft
Product: .net
Published: May 12, 2026
Source: NVD
CVE-2026-42898 CRITICAL - 9.9

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: dynamics_365
Published: May 12, 2026
Source: NVD
CVE-2026-42896 HIGH - 7.8

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_11_24h2
Published: May 12, 2026
Source: NVD
CVE-2026-42893 HIGH - 7.4

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: outlook
Published: May 12, 2026
Source: NVD
CVE-2026-42891 MEDIUM - 6.5

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 12, 2026
Source: NVD
CVE-2026-42838 MEDIUM - 5.4

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 12, 2026
Source: NVD
CVE-2026-42833 CRITICAL - 9.1

Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: dynamics_365
Published: May 12, 2026
Source: NVD
CVE-2026-42832 HIGH - 7.7

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

Vendor: microsoft
Product: excel
Published: May 12, 2026
Source: NVD
CVE-2026-42831 HIGH - 7.8

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Vendor: microsoft
Product: office
Published: May 12, 2026
Source: NVD
CVE-2026-42830 MEDIUM - 6.5

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: azure_monitor_agent
Published: May 12, 2026
Source: NVD
CVE-2026-42825 HIGH - 7.0

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD
CVE-2026-42823 CRITICAL - 9.9

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_logic_apps
Published: May 12, 2026
Source: NVD