Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,015
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,761 - 3,780 of 12,518 CVEs
CVE-2026-23826 HIGH - 7.5

A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation ...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23825 HIGH - 7.5

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may term...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23824 HIGH - 7.5

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may term...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-8431 HIGH - 7.2

An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.ย  This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions 8.0.22 and prior.

Published: May 12, 2026
Source: NVD
CVE-2026-8430 HIGH - 8.1

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through specific nginx configuratio...

Published: May 12, 2026
Source: NVD
CVE-2026-8429 HIGH - 8.8

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability to achieve code execution that bypasses the SPIP security screen protections.

Published: May 12, 2026
Source: NVD
CVE-2026-34682 HIGH - 7.8

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Designer
Published: May 12, 2026
Source: NVD
CVE-2026-34681 HIGH - 7.8

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Designer
Published: May 12, 2026
Source: NVD
CVE-2026-23823 HIGH - 7.2

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only im...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23821 HIGH - 7.2

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operati...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23820 HIGH - 7.2

A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying o...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-23819 HIGH - 8.8

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to com...

Vendor: Hewlett Packard Enterprise (HPE)
Product: ArubaOS (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-44184 HIGH - 8.0

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddre...

Vendor: Cleanuparr
Product: Cleanuparr
Published: May 12, 2026
Source: NVD
CVE-2026-43892 HIGH - 8.8

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16.

Vendor: AntSwordProject
Product: antSword
Published: May 12, 2026
Source: NVD
CVE-2026-42899 HIGH - 7.5

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Vendor: microsoft
Product: .net
Published: May 12, 2026
Source: NVD
CVE-2026-42896 HIGH - 7.8

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_11_24h2
Published: May 12, 2026
Source: NVD
CVE-2026-42893 HIGH - 7.4

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: outlook
Published: May 12, 2026
Source: NVD
CVE-2026-42832 HIGH - 7.7

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

Vendor: microsoft
Product: excel
Published: May 12, 2026
Source: NVD
CVE-2026-42831 HIGH - 7.8

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Vendor: microsoft
Product: office
Published: May 12, 2026
Source: NVD
CVE-2026-42825 HIGH - 7.0

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_10_1607
Published: May 12, 2026
Source: NVD