Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,292
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,701 - 3,720 of 13,241 CVEs
CVE-2026-8407 MEDIUM - 4.3

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Serve...

Published: May 12, 2026
Source: NVD
CVE-2026-40300 MEDIUM - 6.5

Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to recover text that was edited away from other users' messag...

Vendor: zulip
Product: zulip
Published: May 12, 2026
Source: NVD
CVE-2026-25431 MEDIUM - 5.3

Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.

Vendor: WPMU DEV
Product: Hustle
Published: May 12, 2026
Source: NVD
CVE-2026-20914 MEDIUM - 5.5

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result ...

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2026-20905 MEDIUM - 6.6

Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result m...

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2026-20881 MEDIUM - 5.5

Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potenti...

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2026-20782 MEDIUM - 6.6

Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potent...

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2026-20771 MEDIUM - 6.1

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result m...

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2026-20717 MEDIUM - 6.6

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result ...

Vendor: intel
Product: Intel(R) QAT software drivers for Windows
Published: May 12, 2026
Source: NVD
CVE-2023-30059 MEDIUM - 5.4

An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.

Published: May 12, 2026
Source: NVD
CVE-2026-42073 MEDIUM - 6.5

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates a state parameter against...

Vendor: npm
Product: @gitlawb/openclaude
Published: May 12, 2026
Source: GitHub
CVE-2026-8368 MEDIUM - 6.5

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent...

Published: May 12, 2026
Source: NVD
CVE-2026-8109 MEDIUM - 6.5

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

Vendor: ivanti
Product: endpoint_manager
Published: May 12, 2026
Source: NVD
CVE-2026-7431 MEDIUM - 4.4

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.

Vendor: ivanti
Product: secure_access_client
Published: May 12, 2026
Source: NVD
CVE-2026-5061 MEDIUM - 4.7

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.

Published: May 12, 2026
Source: NVD
CVE-2025-70842 MEDIUM - 5.4

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containing malicious JavaScript code. Once uploaded, the script executes in the browser of any user who access...

Published: May 12, 2026
Source: NVD
CVE-2026-44294 MEDIUM - 5.3

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function...

Vendor: npm
Product: protobufjs
Published: May 12, 2026
Source: GitHub
CVE-2026-44292 MEDIUM - 5.3

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-co...

Vendor: npm
Product: protobufjs
Published: May 12, 2026
Source: GitHub
CVE-2026-44288 MEDIUM - 5.3

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf bi...

Vendor: npm
Product: protobufjs
Published: May 12, 2026
Source: GitHub
CVE-2026-8391 MEDIUM - 5.3

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 12, 2026
Source: NVD