Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,016
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,621 - 3,640 of 12,518 CVEs
CVE-2026-21821 HIGH - 8.3

The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks...

Vendor: HCLSoftware
Product: BigFix SCM Reporting
Published: May 13, 2026
Source: NVD
CVE-2025-27853 HIGH - 7.3

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An a...

Published: May 13, 2026
Source: NVD
CVE-2025-27850 HIGH - 7.5

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links when serving content. No mechanisms to restrict those link targets to a specific area of the filesys...

Published: May 13, 2026
Source: NVD
CVE-2026-33377 HIGH - 7.1

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-33376 HIGH - 7.4

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-33583 HIGH - 8.7

Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Agreement Platform. This issue affects Symmetric Key Agreement Platform: before 26.03.

Vendor: Arqit
Product: Symmetric Key Agreement Platform
Published: May 13, 2026
Source: NVD
CVE-2026-30906 HIGH - 7.8

Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

Vendor: Zoom Communications
Product: Zoom Rooms
Published: May 13, 2026
Source: NVD
CVE-2026-30905 HIGH - 7.8

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.

Vendor: Zoom Communications
Product: Zoom Workplace VDI Plugin
Published: May 13, 2026
Source: NVD
CVE-2026-6282 HIGH - 8.1

A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.

Published: May 13, 2026
Source: NVD
CVE-2026-6281 HIGH - 8.8

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

Published: May 13, 2026
Source: NVD
CVE-2026-45740 HIGH - 7.5

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definition...

Vendor: protobufjs_project
Product: protobufjs
Published: May 13, 2026
Source: NVD
CVE-2026-43481 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_reply() genlmsg_reply() hands the reply skb to netlink, and netlink_unicast() consumes it on all return paths, whether the skb is queued successfully or freed on an error path. ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD
CVE-2026-43476 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) instead of the intended __be32 element size (4 bytes). Use sizeof(*meas) to correctly match the buffer ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD
CVE-2026-42945 HIGH - 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement s...

Vendor: F5
Product: NGINX Plus, NGINX Open Source
Published: May 13, 2026
Source: NVD
CVE-2026-42930 HIGH - 8.7

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-42924 HIGH - 8.7

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-42920 HIGH - 7.5

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-42409 HIGH - 7.5

When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are...

Vendor: F5
Product: BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF, BIG-IP Next for Kubernetes
Published: May 13, 2026
Source: NVD
CVE-2026-42406 HIGH - 8.7

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.     Note: Software versions which have reached End of Technical Support (EoTS) are ...

Vendor: F5
Product: BIG-IP, BIG-IQ
Published: May 13, 2026
Source: NVD
CVE-2026-41957 HIGH - 8.8

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP, BIG-IQ
Published: May 13, 2026
Source: NVD