Total CVEs

132,176

Critical Severity

2,835

High Severity

10,141

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,821 - 3,840 of 28,581 CVEs
CVE-2026-45026 MEDIUM - 6.8

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the Processo de Aceitação (html/atendido/processo_aceitacao.php) page, which is executed when user access...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD
CVE-2026-45025 MEDIUM - 6.8

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the "Etapas de um Processo" (html/atendido/etapa_processo.php) page, which is executed when use...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD
CVE-2026-42887 MEDIUM - 4.5

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulnerability exists in the Login Page due to improper sanitization of the authLoginCustomMessage field of the /api/auth-settings endpoint. An attacker with administrative privileges ca...

Vendor: advplyr
Product: audiobookshelf
Published: May 11, 2026
Source: NVD
CVE-2026-42886 MEDIUM - 4.9

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint decompresses the details entry from an uploaded .audiobookshelf ZIP file entirely into memory using zip.entryData(), with no limit on the decompressed size. The upload middleware also...

Vendor: advplyr
Product: audiobookshelf
Published: May 11, 2026
Source: NVD
CVE-2026-42885 MEDIUM - 4.3

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpoint uses String.startsWith() to validate that a resolved file path is within a library folder. This check fails for sibling directories whose names share a common prefix (e.g., /au...

Vendor: advplyr
Product: audiobookshelf
Published: May 11, 2026
Source: NVD
CVE-2026-42884 MEDIUM - 4.3

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/collections/:id endpoints return collections from all libraries without checking whether the requesting user has access to each collection's library. An authenticated user with a...

Vendor: advplyr
Product: audiobookshelf
Published: May 11, 2026
Source: NVD
CVE-2026-42883 MEDIUM - 6.5

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in the URL path, but fetches downloadable items solely by attacker-provided IDs without constraining them...

Vendor: advplyr
Product: audiobookshelf
Published: May 11, 2026
Source: NVD

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with malicious content to funcionario/docdependente_upload.php, the application responds with an overly descriptive error message. This leads to information disclosure, effectively incre...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD
CVE-2026-42872 MEDIUM - 6.1

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_arquivos_etapa.php due to improper handling of user-supplied input. The id_processo parameter is directly embedded into the HTML without sanitization, ...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw was identified at the following endpoint: funcionario/profile_funcionario.php?id_funcionario=2. By injecting a malicious payload into the 'Description' (Descrição) field...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD
CVE-2026-42869 CRITICAL - 10.0

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET...

Vendor: socfortress
Product: CoPilot
Published: May 11, 2026
Source: NVD
CVE-2026-42050 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item. This vulnerability i...

Vendor: ImageMagick
Product: ImageMagick
Published: May 11, 2026
Source: NVD
CVE-2026-36734 HIGH - 8.8

EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient input validation, the attacker is able to execute arbitrary system commands on the device.

Published: May 11, 2026
Source: NVD
CVE-2026-2614 HIGH - 7.5

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the t...

Published: May 11, 2026
Source: NVD
CVE-2022-4988 HIGH - 7.3

Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have kn...

Published: May 11, 2026
Source: NVD

MantisBT Vulnerable to Stored XSS in File Download

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

MantisBT has Stored XSS on Move Attachments Admin Page

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-44635 HIGH - 7.5

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) — including type-safe cod...

Vendor: npm
Product: kysely
Published: May 11, 2026
Source: GitHub
CVE-2026-43979 MEDIUM - 5.0

local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)

Vendor: pip
Product: local-deep-research
Published: May 11, 2026
Source: GitHub
CVE-2026-43898 CRITICAL - 10.0

SandboxJS has a sandbox escape via Function.caller leakage of internal call op

Vendor: npm
Product: @nyariv/sandboxjs
Published: May 11, 2026
Source: GitHub