Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
Showing 3,861 - 3,880 of 13,084 CVEs
CVE-2026-7377 HIGH - 8.7

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers...

Vendor: gitlab
Product: gitlab
Published: May 14, 2026
Source: NVD
CVE-2026-6073 HIGH - 8.7

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

Vendor: gitlab
Product: gitlab
Published: May 14, 2026
Source: NVD
CVE-2026-5396 HIGH - 8.2

The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` qu...

Published: May 14, 2026
Source: NVD
CVE-2026-1659 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.

Vendor: gitlab
Product: gitlab
Published: May 14, 2026
Source: NVD
CVE-2025-14870 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation.

Vendor: GitLab
Product: GitLab
Published: May 14, 2026
Source: NVD
CVE-2025-14869 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted payloads on certain API endpoints.

Vendor: GitLab
Product: GitLab
Published: May 14, 2026
Source: NVD
CVE-2026-46446 HIGH - 7.1

SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.

Vendor: Alinto
Product: SOGo
Published: May 14, 2026
Source: NVD
CVE-2026-46445 HIGH - 7.1

SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.

Vendor: Alinto
Product: SOGo
Published: May 14, 2026
Source: NVD
CVE-2026-46419 HIGH - 7.5

Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.

Vendor: Yubico
Product: webauthn-server-core
Published: May 14, 2026
Source: NVD
CVE-2026-32991 HIGH - 7.1

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

Vendor: WebPros
Product: cPanel, WP Squared, cPanel (CloudLinux 6, CentOS 6)
Published: May 13, 2026
Source: NVD
CVE-2026-29206 HIGH - 8.1

Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

Vendor: WebPros
Product: cPanel, WP Squared, cPanel (CloudLinux 6, CentOS 6)
Published: May 13, 2026
Source: NVD
CVE-2026-44478 HIGH - 7.5

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config overwrites. However, GET /v1/onboarding/config still ...

Vendor: hoppscotch
Product: hoppscotch
Published: May 13, 2026
Source: NVD
CVE-2026-44447 HIGH - 8.8

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44446 HIGH - 8.8

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 15.104.3 and 16...

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-42463 HIGH - 8.1

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoint...

Vendor: dataease
Product: SQLBot
Published: May 13, 2026
Source: NVD
CVE-2026-32993 HIGH - 8.3

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-32992 HIGH - 8.2

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-29205 HIGH - 8.6

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Vendor: WebPros
Product: cPanel, WP Squared
Published: May 13, 2026
Source: NVD
CVE-2026-45708 HIGH - 7.2

CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php โ€ฆ ?> into the Invoice Editor. The next time any admin clicks Print on any order, the rendered template is written to files/print.<md5>.php. files/.htaccess ships an expl...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45229 HIGH - 8.8

Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to perm...

Vendor: Cp0204
Product: quark-auto-save
Published: May 13, 2026
Source: NVD