Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
Showing 361 - 380 of 1,466 CVEs

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves be...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-8492 LOW - 2.7

Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.

Published: May 19, 2026
Source: NVD
CVE-2026-8491 LOW - 3.7

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.

Published: May 19, 2026
Source: NVD

Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, the /__nuxt_island/* endpoint accepts attacker-controlled props query/body...

Vendor: npm
Product: nuxt
Published: May 19, 2026
Source: GitHub

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token&...

Vendor: pip
Product: strawberry-graphql
Published: May 19, 2026
Source: GitHub

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path contain...

Vendor: go
Product: github.com/go-git/go-git/v5
Published: May 19, 2026
Source: GitHub

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

Vendor: OpenHarmony
Product: OpenHarmony
Published: May 19, 2026
Source: NVD

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a pe...

Vendor: jarrodwatts
Product: claude-hud
Published: May 18, 2026
Source: NVD

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can therefore point OBI at ker...

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object (rather than a String) to Faraday::Connection#build_exclusive_url. This...

Vendor: rubygems
Product: faraday
Published: May 18, 2026
Source: GitHub
CVE-2026-8803 LOW - 3.7

A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have...

Published: May 18, 2026
Source: NVD
CVE-2026-6333 LOW - 3.5

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermos...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-4643 LOW - 3.5

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, lea...

Published: May 18, 2026
Source: NVD
CVE-2026-4286 LOW - 3.1

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api. Mattermos...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-6334 LOW - 3.1

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token exchange request.. Mat...

Published: May 18, 2026
Source: NVD
CVE-2026-4273 LOW - 3.7

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token via sending a ...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD
CVE-2026-3495 LOW - 3.8

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those ...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD