Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
Showing 3,941 - 3,960 of 13,084 CVEs
CVE-2026-44797 HIGH - 8.5

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allo...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-45134 HIGH - 7.1

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt ma...

Vendor: pip
Product: langsmith
Published: May 13, 2026
Source: GitHub
CVE-2026-44724 HIGH - 7.8

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained int...

Vendor: npm
Product: systeminformation
Published: May 13, 2026
Source: GitHub
CVE-2026-4609 HIGH - 7.1

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level ...

Published: May 13, 2026
Source: NVD

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-...

Vendor: mtrudel
Product: bandit
Published: May 13, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1/socket.ex ignores the caller-supplied :length opti...

Vendor: mtrudel
Product: bandit
Published: May 13, 2026
Source: NVD
CVE-2026-37430 HIGH - 7.3

An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.

Published: May 13, 2026
Source: NVD
CVE-2026-6177 HIGH - 7.2

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts A...

Published: May 13, 2026
Source: NVD
CVE-2026-3425 HIGH - 8.8

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above...

Published: May 13, 2026
Source: NVD
CVE-2026-35506 HIGH - 7.2

ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.

Vendor: ELECOM CO.,LTD.
Product: WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, WRC-W702-B
Published: May 13, 2026
Source: NVD
CVE-2026-6276 HIGH - 7.5

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second req...

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-5773 HIGH - 7.5

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in th...

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-4798 HIGH - 7.5

The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published: May 13, 2026
Source: NVD
CVE-2026-6929 HIGH - 7.5

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of suff...

Published: May 13, 2026
Source: NVD
CVE-2026-44612 HIGH - 7.8

Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.

Vendor: Bytello
Product: Bytello Share (Windows Edition) installer executable
Published: May 13, 2026
Source: NVD
CVE-2026-21020 HIGH - 7.8

Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.

Vendor: samsung
Product: android
Published: May 13, 2026
Source: NVD
CVE-2026-7635 HIGH - 8.1

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the User-Agent HTTP header before storing it in the logmeta tabl...

Published: May 13, 2026
Source: NVD
CVE-2026-8336 HIGH - 7.5

After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in...

Vendor: mongodb
Product: mongodb
Published: May 13, 2026
Source: NVD
CVE-2026-8201 HIGH - 8.8

A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query. This issue impacts Mongo...

Vendor: mongodb
Product: mongodb
Published: May 13, 2026
Source: NVD
CVE-2026-8053 HIGH - 8.8

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-seri...

Vendor: mongodb
Product: mongodb
Published: May 13, 2026
Source: NVD