Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,016
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,661 - 3,680 of 12,518 CVEs
CVE-2026-20916 HIGH - 8.1

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IQ
Published: May 13, 2026
Source: NVD
CVE-2025-28344 HIGH - 7.5

striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.

Published: May 13, 2026
Source: NVD
CVE-2025-28343 HIGH - 7.5

striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.

Published: May 13, 2026
Source: NVD
CVE-2024-55045 HIGH - 7.3

Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.

Published: May 13, 2026
Source: NVD
CVE-2020-37226 HIGH - 7.1

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' ...

Vendor: Joomsky
Product: J2 JOBS
Published: May 13, 2026
Source: NVD
CVE-2020-37224 HIGH - 7.1

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' ...

Vendor: Joomsky
Product: J2 JOBS
Published: May 13, 2026
Source: NVD
CVE-2020-37223 HIGH - 7.8

IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to...

Vendor: Iobit
Product: IObit Uninstaller
Published: May 13, 2026
Source: NVD
CVE-2020-37222 HIGH - 7.2

Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoint. Attackers can send POST requests to /web/?c=bbs&a=reply with HTML and JavaScript payloads in ...

Vendor: Kuicms
Product: Kuicms Php EE
Published: May 13, 2026
Source: NVD
CVE-2020-37221 HIGH - 8.4

Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encode...

Vendor: Drive-software
Product: Atomic Alarm Clock
Published: May 13, 2026
Source: NVD
CVE-2020-37220 HIGH - 7.5

Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then ...

Vendor: www.huawei.com
Product: Huawei HG630 Router
Published: May 13, 2026
Source: NVD
CVE-2020-37219 HIGH - 7.5

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories ...

Vendor: Fabrikar
Product: com_fabrik
Published: May 13, 2026
Source: NVD
CVE-2020-37218 HIGH - 8.2

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwpla...

Vendor: Hdwplayer
Product: com_hdwplayer
Published: May 13, 2026
Source: NVD

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/getLocalGraph, POST /api/sync/setSyncInterval, POST /api/storage/updateRecentDocViewTime, POST /api/st...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45152 HIGH - 7.8

uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files using /bin/bash -c. Because the check field is loaded directly from untrusted JSON metadata without va...

Vendor: go
Product: gitlab.com/uniget-org/cli
Published: May 13, 2026
Source: GitHub
CVE-2026-45137 HIGH - 8.2

Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs ...

Vendor: rust
Product: anchor-lang
Published: May 13, 2026
Source: GitHub
CVE-2026-45136 HIGH - 7.8

claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-con...

Vendor: npm
Product: claude-code-cache-fix
Published: May 13, 2026
Source: GitHub
CVE-2026-44798 HIGH - 7.1

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the current_head field on the record, which was not intended to be user-editable. Doing so could cause Naut...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44797 HIGH - 8.5

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allo...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-45134 HIGH - 7.1

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt ma...

Vendor: pip
Product: langsmith
Published: May 13, 2026
Source: GitHub
CVE-2026-44724 HIGH - 7.8

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained int...

Vendor: npm
Product: systeminformation
Published: May 13, 2026
Source: GitHub