Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,277
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,781 - 3,800 of 13,243 CVEs
CVE-2026-34258 MEDIUM - 4.7

SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low ...

Vendor: SAP_SE
Product: SAPUI5 (Search UI)
Published: May 12, 2026
Source: NVD
CVE-2026-27682 MEDIUM - 4.7

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the i...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Published: May 12, 2026
Source: NVD
CVE-2026-0502 MEDIUM - 5.4

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality ...

Published: May 12, 2026
Source: NVD
CVE-2026-8349 MEDIUM - 4.3

A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 8a4c...

Published: May 12, 2026
Source: NVD
CVE-2026-8346 MEDIUM - 6.3

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.

Vendor: dlink
Product: dir-816_firmware
Published: May 12, 2026
Source: NVD
CVE-2026-8345 MEDIUM - 6.3

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exp...

Vendor: dlink
Product: dir-816_firmware
Published: May 11, 2026
Source: NVD
CVE-2026-43911 MEDIUM - 6.8

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, email change, org admin password reset, emergency access ...

Vendor: dani-garcia
Product: vaultwarden
Published: May 11, 2026
Source: NVD
CVE-2026-34962 MEDIUM - 6.2

barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry length values are non-zero. Attackers can supply a malicious ext4 filesystem image with a cr...

Vendor: barebox
Product: barebox
Published: May 11, 2026
Source: NVD
CVE-2026-8344 MEDIUM - 6.3

A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the p...

Vendor: dlink
Product: dir-816_firmware
Published: May 11, 2026
Source: NVD
CVE-2026-7010 MEDIUM - 6.5

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values. An attacker who controls one...

Published: May 11, 2026
Source: NVD
CVE-2026-44695 MEDIUM - 5.8

Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can obtain a Slack OAuth code for the same Outline Slack client can make a logged-in...

Vendor: outline
Product: outline
Published: May 11, 2026
Source: NVD
CVE-2026-43889 MEDIUM - 6.5

Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both collectionId and documentId simultaneously and, when published=false, only verifies read access for eachโ€”skipping the "share" permission check. A subsequent shares.update au...

Vendor: outline
Product: outline
Published: May 11, 2026
Source: NVD
CVE-2026-34961 MEDIUM - 6.2

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.c. Attackers can supply a malicious ext4 filesystem image via USB, SD card, or network boot to trigge...

Vendor: barebox
Product: barebox
Published: May 11, 2026
Source: NVD
CVE-2026-34960 MEDIUM - 6.5

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds. An attacker on the same broadcast domain can send a crafted DHCP Offer or ACK...

Vendor: barebox
Product: barebox
Published: May 11, 2026
Source: NVD
CVE-2026-45046 MEDIUM - 5.5

Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine what content is logged to a local sqlite database. The README incorrectly mentions that the default log level is minimal while it is standard. Source code review shows sensitive file-...

Vendor: go
Product: github.com/safedep/gryph
Published: May 11, 2026
Source: GitHub
CVE-2026-43666 MEDIUM - 6.2

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able t...

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published: May 11, 2026
Source: NVD
CVE-2026-43659 MEDIUM - 4.7

A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.

Vendor: Apple
Product: iOS and iPadOS, macOS, visionOS
Published: May 11, 2026
Source: NVD
CVE-2026-43653 MEDIUM - 6.2

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS
Published: May 11, 2026
Source: NVD
CVE-2026-39869 MEDIUM - 4.3

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file ma...

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published: May 11, 2026
Source: NVD
CVE-2026-28996 MEDIUM - 5.5

A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published: May 11, 2026
Source: NVD