Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 4,061 - 4,080 of 13,249 CVEs
CVE-2026-44309 MEDIUM - 5.3

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking the signature, instead of verifying against the raw git o...

Vendor: go
Product: github.com/sigstore/gitsign
Published: May 08, 2026
Source: GitHub
CVE-2026-44831 MEDIUM - 4.8

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

Vendor: composer
Product: snipe/snipe-it
Published: May 08, 2026
Source: GitHub
CVE-2026-44568 MEDIUM - 4.8

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overlay Content" using marked.parse() inside {@html} with an incorrect DOMPurify application ord...

Vendor: pip
Product: open-webui
Published: May 08, 2026
Source: GitHub
CVE-2026-42209 MEDIUM - 6.5

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both set_retained_message_defer_timeout and set_retained_message_defer_timeout_spread are configured to non-default values...

Vendor: halfgaar
Product: FlashMQ
Published: May 08, 2026
Source: NVD
CVE-2026-42202 MEDIUM - 6.5

nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard> middleware. Any user authenticated on the configured guard could call the endpoint and flip bo...

Vendor: almirhodzic
Product: nova-toggle-5
Published: May 08, 2026
Source: NVD
CVE-2026-42199 MEDIUM - 6.2

Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relationship between the grid’s logical dimensions and its backing storage. After the internal invariant is broken, the safe API get() may invoke get_unchec...

Vendor: becheran
Product: grid
Published: May 08, 2026
Source: NVD
CVE-2026-42192 MEDIUM - 5.4

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email body content created by authenticated project members is stored and later rendered in the admin dashboa...

Vendor: useplunk
Product: plunk
Published: May 08, 2026
Source: NVD
CVE-2026-44214 MEDIUM - 5.8

eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events...

Vendor: npm
Product: eventsource-encoder
Published: May 08, 2026
Source: GitHub
CVE-2026-44213 MEDIUM - 6.5

The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the INSTANA_ENDPOINT_P...

Vendor: nuget
Product: OpenTelemetry.Exporter.Instana
Published: May 08, 2026
Source: GitHub
CVE-2026-44247 MEDIUM - 6.8

Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluster pod that can reach the webhook endpoint may send an arbitrarily large request body, potentially cau...

Vendor: go
Product: volcano.sh/volcano
Published: May 08, 2026
Source: GitHub
CVE-2026-44200 MEDIUM - 6.5

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and potentially publish ...

Vendor: pip
Product: wagtail
Published: May 08, 2026
Source: GitHub
CVE-2026-44201 MEDIUM - 5.3

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulner...

Vendor: pip
Product: wagtail
Published: May 08, 2026
Source: GitHub
CVE-2026-44199 MEDIUM - 6.5

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they do have access to...

Vendor: pip
Product: wagtail
Published: May 08, 2026
Source: GitHub
CVE-2026-44198 MEDIUM - 4.3

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7...

Vendor: pip
Product: wagtail
Published: May 08, 2026
Source: GitHub
CVE-2026-44197 MEDIUM - 6.5

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could potentially result in disc...

Vendor: pip
Product: wagtail
Published: May 08, 2026
Source: GitHub
CVE-2026-42282 MEDIUM - 4.3

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MCP tools/call requests had their full arguments and JSON-RPC params written to server logs by the requ...

Vendor: czlonkowski
Product: n8n-mcp
Published: May 08, 2026
Source: NVD
CVE-2026-42190 MEDIUM - 5.3

RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the vic...

Vendor: redwoodjs
Product: sdk
Published: May 08, 2026
Source: NVD
CVE-2026-42185 MEDIUM - 5.5

People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current domain access) to the ...

Vendor: suitenumerique
Product: people
Published: May 08, 2026
Source: NVD
CVE-2026-42181 MEDIUM - 6.5

Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied post URLs and, under the default StoreLinkPreviews image mode, downloads the preview image through local pict-rs. While the top-level page URL is checked against internal IP ran...

Vendor: LemmyNet
Product: lemmy
Published: May 08, 2026
Source: NVD
CVE-2026-42180 MEDIUM - 6.3

Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-privileged user to create a link post through POST /api/v3/post. When a post is created in a public community, the backend asynchronously sends a Webmention to the attacker-controlled ...

Vendor: LemmyNet
Product: lemmy
Published: May 08, 2026
Source: NVD