Total CVEs

132,202

Critical Severity

2,836

High Severity

10,146

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,961 - 3,980 of 28,607 CVEs
CVE-2026-33361 HIGH - 7.5

In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model.

Vendor: Meari
Product: com.meari.sdk
Published: May 11, 2026
Source: NVD
CVE-2026-33359 HIGH - 7.5

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.

Vendor: Meari
Product: Alibaba OSS Hosted
Published: May 11, 2026
Source: NVD
CVE-2026-33357 HIGH - 7.5

In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearicloud.com can be abused to retrieve WAN IP data for arbitrary devices. The root cause is ...

Vendor: Meari
Product: com.meari.sdk
Published: May 11, 2026
Source: NVD
CVE-2026-33356 HIGH - 7.7

In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at p...

Vendor: Meari
Product: IoT Cloud MQTT Broker EMQX
Published: May 11, 2026
Source: NVD
CVE-2026-31254 HIGH - 7.3

The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python eval() function as a Hydra configuration resolver under the name eval. This allows configuration file...

Published: May 11, 2026
Source: NVD
CVE-2026-31253 HIGH - 7.3

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in checkpoint.py and the checkpoint loading code in eval.py use to...

Published: May 11, 2026
Source: NVD
CVE-2026-31252 MEDIUM - 5.7

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load() to load model weight files (e.g., llm.pt, flow.pt, hift.pt) without enabling the security-restricti...

Published: May 11, 2026
Source: NVD
CVE-2026-31251 HIGH - 7.3

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads the speech synthesis model from a user-specified directory using torch.load() without enabling the w...

Published: May 11, 2026
Source: NVD
CVE-2026-31250 HIGH - 7.3

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) for model averaging using torch.load() without enabling the we...

Published: May 11, 2026
Source: NVD
CVE-2026-31249 HIGH - 7.3

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embeddings, speaker embeddings, speech tokens) using torch.load() w...

Published: May 11, 2026
Source: NVD
CVE-2026-31248 HIGH - 7.5

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can craft a malicious XML file with nested entity definitions ...

Published: May 11, 2026
Source: NVD
CVE-2026-45109 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-45061 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a single substring check: url.includes(".tar.gz"). Any URL containing .tar.gz anywhere in the string โ€” in the path, query string, or fragment โ€”...

Vendor: npm
Product: budibase
Published: May 11, 2026
Source: GitHub
CVE-2026-45047 HIGH - 7.5

bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read size. An unauthenticated remote attacker can stream...

Vendor: go
Product: github.com/xddxdd/bird-lg-go
Published: May 11, 2026
Source: GitHub
CVE-2026-8292 MEDIUM - 4.3

A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in the library /lib/sbi/conv.c of the component NRF. Such manipulation of the argument hnrf-uri leads to denial of service. The attack may be performed from remote. The exploit has be...

Vendor: open5gs
Product: open5gs
Published: May 11, 2026
Source: NVD
CVE-2026-8291 MEDIUM - 4.3

A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the file lib/sbi/nnrf-handler.c of the component NRF. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been made available t...

Vendor: open5gs
Product: open5gs
Published: May 11, 2026
Source: NVD
CVE-2026-7820 MEDIUM - 6.5

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server...

Published: May 11, 2026
Source: NVD
CVE-2026-7819 HIGH - 8.1

Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside thei...

Published: May 11, 2026
Source: NVD
CVE-2026-7818 HIGH - 7.0

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any HMAC integrity check. Any file dropped into the sessions ...

Published: May 11, 2026
Source: NVD
CVE-2026-7817 MEDIUM - 6.5

Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read arbitrary server-side files...

Published: May 11, 2026
Source: NVD