Total CVEs

133,082

Critical Severity

2,916

High Severity

10,594

Last 7 Days

2,053
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,601 - 3,620 of 29,487 CVEs

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/Web...

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub
CVE-2026-45299 MEDIUM - 5.4

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, the profile_image_url field on the user profile update form accepted arbitrary data: URI values without MIME-type validation, resulting in a XSS vulnerability. This vulnerability is fix...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reach...

Vendor: go
Product: github.com/kumahq/kuma
Published: May 14, 2026
Source: GitHub
CVE-2026-8621 HIGH - 8.8

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a sha...

Published: May 14, 2026
Source: NVD
CVE-2026-44633 HIGH - 8.1

Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can cha...

Vendor: LiveHelperChat
Product: livehelperchat
Published: May 14, 2026
Source: NVD
CVE-2026-44592 CRITICAL - 9.4

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker without any credentials by sending a fresh, never-registered worker UUID. The resulting session has PeerA...

Vendor: wavelens
Product: gradient
Published: May 14, 2026
Source: NVD
CVE-2026-44586 HIGH - 8.3

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron wi...

Vendor: siyuan-note
Product: siyuan
Published: May 14, 2026
Source: NVD

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start th...

Vendor: midoks
Product: mdserver-web
Published: May 14, 2026
Source: NVD
CVE-2026-38740 MEDIUM - 5.3

Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Session Description Protocol (SDP), including ICE credentials and candidates, in cleartext over network interfaces. An attacker with network visibility can i...

Published: May 14, 2026
Source: NVD

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result,...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP
Published: May 14, 2026
Source: NVD

ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override

Vendor: pip
Product: ethyca-fides
Published: May 14, 2026
Source: GitHub
CVE-2026-45011 HIGH - 7.3

Apostrophe has stored XSS via javascript: URL in Image Widget Link

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45013 HIGH - 8.1

Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45012 HIGH - 7.6

Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-44990 CRITICAL - 9.3

Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

Vendor: npm
Product: sanitize-html
Published: May 14, 2026
Source: GitHub
CVE-2026-44973 HIGH - 8.1

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was ...

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 14, 2026
Source: GitHub

dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub
CVE-2026-44968 MEDIUM - 6.3

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.

Published: May 14, 2026
Source: NVD