Total CVEs

132,202

Critical Severity

2,836

High Severity

10,146

Last 7 Days

1,628
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 4,021 - 4,040 of 28,607 CVEs
CVE-2026-44581 MEDIUM - 4.7

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived f...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub

Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44580 MEDIUM - 6.1

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped ...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44579 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurati...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44577 MEDIUM - 5.9

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cau...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44578 HIGH - 8.6

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server t...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44576 MEDIUM - 5.4

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44575 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetchin...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44574 HIGH - 8.1

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44573 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 Β§6.9.5.1 β€” it could send a NAS Security Mode Command while an N2 handover was still pending (and vice versa). Concurre...

Vendor: go
Product: github.com/ellanetworks/core
Published: May 11, 2026
Source: GitHub
CVE-2026-44475 MEDIUM - 6.1

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with ...

Vendor: go
Product: github.com/ellanetworks/core
Published: May 11, 2026
Source: GitHub
CVE-2026-44473 HIGH - 7.1

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-conne...

Vendor: go
Product: github.com/ellanetworks/core
Published: May 11, 2026
Source: GitHub

python-liquid: Absolute paths escape filesystem loader search path

Vendor: pip
Product: python-liquid
Published: May 11, 2026
Source: GitHub
CVE-2026-44432 HIGH - 7.5

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.dra...

Vendor: pip
Product: urllib3
Published: May 11, 2026
Source: GitHub
CVE-2026-44431 HIGH - 5.3

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

Vendor: pip
Product: urllib3
Published: May 11, 2026
Source: GitHub

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose valu...

Vendor: go
Product: github.com/go-git/go-git/v6
Published: May 11, 2026
Source: GitHub
CVE-2026-44971 HIGH - 8.2

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an ...

Vendor: pip
Product: guarddog
Published: May 11, 2026
Source: GitHub
CVE-2026-44972 MEDIUM - 5.0

GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal control characters. A malicious package can therefore inject AN...

Vendor: pip
Product: guarddog
Published: May 11, 2026
Source: GitHub
CVE-2026-44902 HIGH - 7.5

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid ...

Vendor: npm
Product: @opentelemetry/exporter-prometheus
Published: May 11, 2026
Source: GitHub