Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,302
Quick preset (or use dates below)
Clear Filters
Showing 3,841 - 3,860 of 13,622 CVEs

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.0.0 to 2.28.1, lack of validation of filter_target parameter on return_dynamic_filters.php (normally used as an AJAX in View Issues Page) allows an attacker to inject arbitrary HTML if the target is a TEXTAREA custom field. This v...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-41159 MEDIUM - 5.3

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration op...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub
CVE-2026-41150 MEDIUM - 5.3

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then ...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diag...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes us...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-enc...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-39960 MEDIUM - 5.4

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a textarea custom field's contents in the Update Issue page, (bug_update_page.php) allowing an attacker to inject HTML and, if CSP settings permit, exec...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page after losing access to the parent private issue. This issue has been fixed in version 2.28.2.

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-34754 MEDIUM - 4.3

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and download their own attachments from an Issue created by another user even after it becomes private, bypassing read access revocation. The loss of confidentiality caused by this vulnerab...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization Bypass through the private issue monitoring feature . Using a crafted POST request to bug_monitor_add.php, a user with project-level access can add themselves as a monitor for a p...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnerability where insufficient access control checks in ProjectUsersAddCommand (manage_proj_user_add.php) allow users having manage_project_threshold access level (manager by defaul...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-8318 MEDIUM - 5.3

A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by this vulnerability is the function toc_transformer of the file pageindex/page_index.py of the component PDF Table of Contents Handler. The manipulation results in infinite loop. The...

Published: May 11, 2026
Source: NVD
CVE-2026-45222 MEDIUM - 6.1

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json. ...

Vendor: steipete
Product: summarize
Published: May 11, 2026
Source: NVD
CVE-2026-4893 MEDIUM - 5.3

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

Published: May 11, 2026
Source: NVD
CVE-2026-4891 MEDIUM - 5.3

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

Published: May 11, 2026
Source: NVD
CVE-2026-45005 MEDIUM - 6.0

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until ga...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45003 MEDIUM - 5.0

OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45002 MEDIUM - 5.3

OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45000 MEDIUM - 5.0

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during n...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD