Total CVEs

132,202

Critical Severity

2,836

High Severity

10,146

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,941 - 3,960 of 28,607 CVEs
CVE-2026-3609 HIGH - 7.8

Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cross reference to KVE 2023-5589 (https://krcert.or.kr)

Vendor: wellbia
Product: xigncode3
Published: May 11, 2026
Source: NVD

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

Published: May 11, 2026
Source: NVD
CVE-2026-38569 MEDIUM - 5.4

HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add or POST /feedback/add.

Published: May 11, 2026
Source: NVD
CVE-2026-38568 HIGH - 8.1

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve records by the user-supplied ID without verifying that the requesting user is the owner o...

Published: May 11, 2026
Source: NVD
CVE-2026-38567 CRITICAL - 9.8

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker can bypass authentication by supplying a crafted username (e.g. admin'--) or extract the full con...

Published: May 11, 2026
Source: NVD
CVE-2026-38566 HIGH - 8.1

HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission at /feedback/add/<id>, interview scheduling at /interviews/add) are vulnerable to CSRF. A...

Published: May 11, 2026
Source: NVD
CVE-2026-36983 HIGH - 7.3

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

Vendor: dlink
Product: dcs-932l_firmware
Published: May 11, 2026
Source: NVD
CVE-2026-36962 HIGH - 7.3

SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution by writing malicious files to the server's file system via the keyword parameter in the /index/...

Published: May 11, 2026
Source: NVD
CVE-2026-34095 MEDIUM - 6.1

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD
CVE-2026-34093 MEDIUM - 5.3

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD
CVE-2026-30635 HIGH - 8.1

Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/server.js when a user reads from an external FORGE_BASE_URL.

Published: May 11, 2026
Source: NVD
CVE-2026-2393 HIGH - 7.1

A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a user-controlled `url` parameter without validation, and the `_send_webhook_request()` function in `mlflow/webhooks/delivery.py` sends...

Published: May 11, 2026
Source: NVD
CVE-2026-2291 HIGH - 7.3

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

Published: May 11, 2026
Source: NVD

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global profile despite not having manage_global_profile_threshold, by tampering with the user_id p...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-25244 CRITICAL - 9.8

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metachara...

Vendor: npm
Product: @wdio/browserstack-service
Published: May 11, 2026
Source: GitHub
CVE-2026-44738 HIGH - 7.7

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration โ€” including all plugin secrets (SMTP passwords, AWS keys, OAuth client secrets...

Vendor: getgrav
Product: grav
Published: May 11, 2026
Source: NVD
CVE-2026-42603 HIGH - 8.8

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_target (privileged trigger) but checks out and executes code directly from the attacker's fork, en...

Vendor: OWASP-BLT
Product: BLT
Published: May 11, 2026
Source: NVD
CVE-2026-36906 MEDIUM - 6.1

Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function

Published: May 11, 2026
Source: NVD
CVE-2026-33362 HIGH - 8.6

In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.

Vendor: Meari
Product: com.meari.sdk
Published: May 11, 2026
Source: NVD