Total CVEs

132,202

Critical Severity

2,836

High Severity

10,146

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,861 - 3,880 of 28,607 CVEs
CVE-2022-4988 HIGH - 7.3

Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have kn...

Published: May 11, 2026
Source: NVD

MantisBT Vulnerable to Stored XSS in File Download

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

MantisBT has Stored XSS on Move Attachments Admin Page

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-44635 HIGH - 7.5

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) โ€” including type-safe cod...

Vendor: npm
Product: kysely
Published: May 11, 2026
Source: GitHub
CVE-2026-43979 MEDIUM - 5.0

local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)

Vendor: pip
Product: local-deep-research
Published: May 11, 2026
Source: GitHub
CVE-2026-43898 CRITICAL - 10.0

SandboxJS has a sandbox escape via Function.caller leakage of internal call op

Vendor: npm
Product: @nyariv/sandboxjs
Published: May 11, 2026
Source: GitHub

MantisBT has a Private Bugnote Attachment Content Leak via REST API

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea Field

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mermaid: Improper sanitization of configuration leads to CSS injection

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diag...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes us...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerability is caused by incorrect escaping of a saved filter's owner, allowing an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON. Note that By default...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker to inject HTML. While this is generally not directly actionable as modern browsers will URL-enc...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading a crafted attachment to any issue that, when accessed vi...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated user to inject arbitrary HTML by updating their account's font family. Upon exploitation, an XSS payload would be reflected on every MantisBT page. Leveraging another vulnerabil...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-39960 MEDIUM - 5.4

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a textarea custom field's contents in the Update Issue page, (bug_update_page.php) allowing an attacker to inject HTML and, if CSP settings permit, exec...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-39850 HIGH - 7.4

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a...

Vendor: composer
Product: yiisoft/yii2
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page after losing access to the parent private issue. This issue has been fixed in version 2.28.2.

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub