Total CVEs

132,176

Critical Severity

2,835

High Severity

10,141

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,901 - 3,920 of 28,581 CVEs
CVE-2026-43894 MEDIUM - 6.2

jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-...

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD
CVE-2026-43640 HIGH - 8.1

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.

Vendor: bitwarden
Product: server
Published: May 11, 2026
Source: NVD
CVE-2026-43639 HIGH - 8.0

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization; self-hosted installations a...

Vendor: bitwarden
Product: server
Published: May 11, 2026
Source: NVD
CVE-2026-43638 MEDIUM - 5.4

Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side permission check to b...

Vendor: bitwarden
Product: server
Published: May 11, 2026
Source: NVD

Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerabil...

Vendor: elie222
Product: inbox-zero
Published: May 11, 2026
Source: NVD

Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RSA-AES security type handler. An unauthenticated remote attacker who can reach the VNC listening socket can send a crafted security type 5 (RSA-AES) or security type 129 (RSA-AES-25...

Vendor: any1
Product: neatvnc
Published: May 11, 2026
Source: NVD
CVE-2026-42858 HIGH - 8.5

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed directly to requests.get() i...

Vendor: openedx
Product: openedx-platform
Published: May 11, 2026
Source: NVD
CVE-2026-42857 MEDIUM - 4.6

Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove <style> tags from user-generated discussion post content. This content is rendered with Django's |safe ...

Vendor: openedx
Product: openedx-platform
Published: May 11, 2026
Source: NVD
CVE-2026-42316 MEDIUM - 6.5

kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping e...

Vendor: Azure
Product: kafka-sink-azure-kusto
Published: May 11, 2026
Source: NVD
CVE-2026-41431 HIGH - 8.0

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signature...

Vendor: zen-browser
Product: desktop
Published: May 11, 2026
Source: NVD
CVE-2026-41257 MEDIUM - 5.5

jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond โ‰ˆ1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used ...

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD
CVE-2026-41256 MEDIUM - 5.5

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the...

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD
CVE-2026-41250 MEDIUM - 5.7

Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.

Vendor: taigaio
Product: taiga-front
Published: May 11, 2026
Source: NVD
CVE-2026-40612 MEDIUM - 5.5

jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD
CVE-2026-3609 HIGH - 7.8

Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cross reference to KVE 2023-5589 (https://krcert.or.kr)

Vendor: wellbia
Product: xigncode3
Published: May 11, 2026
Source: NVD

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

Published: May 11, 2026
Source: NVD
CVE-2026-38569 MEDIUM - 5.4

HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add or POST /feedback/add.

Published: May 11, 2026
Source: NVD
CVE-2026-38568 HIGH - 8.1

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve records by the user-supplied ID without verifying that the requesting user is the owner o...

Published: May 11, 2026
Source: NVD
CVE-2026-38567 CRITICAL - 9.8

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker can bypass authentication by supplying a crafted username (e.g. admin'--) or extract the full con...

Published: May 11, 2026
Source: NVD
CVE-2026-38566 HIGH - 8.1

HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission at /feedback/add/<id>, interview scheduling at /interviews/add) are vulnerable to CSRF. A...

Published: May 11, 2026
Source: NVD