Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,015
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,701 - 3,720 of 12,518 CVEs
CVE-2026-5371 HIGH - 7.1

The MonsterInsights โ€“ Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and inc...

Published: May 12, 2026
Source: NVD
CVE-2026-44548 HIGH - 8.1

ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDelete.php causes a logged-in ChurchCRM user with the relevant role to silently delete records, including...

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD
CVE-2026-43685 HIGH - 7.2

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.

Vendor: Claris
Product: FileMaker Cloud
Published: May 12, 2026
Source: NVD
CVE-2026-43680 HIGH - 7.2

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operating system commands on the underlying host. This issue is fixed in FileMaker Cloud 2.22.0.5.

Vendor: Claris
Product: FileMaker Cloud
Published: May 12, 2026
Source: NVD
CVE-2026-42289 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token validation. An unauthenticated attacker can craft a malicious HTML page that, when visited by an authentic...

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD
CVE-2026-1250 HIGH - 7.5

The Court Reservation โ€“ Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the โ€˜idโ€™ parameter in all versions up to, and including, 1.10.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...

Published: May 12, 2026
Source: NVD
CVE-2026-44660 HIGH - 7.5

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation...

Vendor: pip
Product: ujson
Published: May 12, 2026
Source: GitHub
CVE-2026-44648 HIGH - 7.5

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authentication, storing all session data (user handle, perm...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44594 HIGH - 7.5

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return ...

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: May 12, 2026
Source: GitHub
CVE-2026-8449 HIGH - 8.8

Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subau...

Published: May 12, 2026
Source: NVD
CVE-2026-45227 HIGH - 8.8

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __impo...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45226 HIGH - 7.1

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds poin...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45225 HIGH - 7.6

Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted filename with traversal sequences. Attackers can exploit the unvalidated filename parameter in the u...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-44871 HIGH - 7.2

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying opera...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-44296 HIGH - 7.5

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and its first bytes do not parse as a valid TLS ClientH...

Vendor: deskflow
Product: deskflow
Published: May 12, 2026
Source: NVD
CVE-2026-44260 HIGH - 8.1

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no event handler c...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD
CVE-2026-44015 HIGH - 8.5

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forward...

Vendor: 0xJacky
Product: nginx-ui
Published: May 12, 2026
Source: NVD
CVE-2026-42855 HIGH - 7.5

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp32 computes the authentication hash using the URI field from the client's Authorization header, ...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-42268 HIGH - 7.5

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @veri...

Vendor: owasp-modsecurity
Product: ModSecurity
Published: May 12, 2026
Source: NVD
CVE-2026-26289 HIGH - 8.2

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD