Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,008
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,081 - 4,100 of 12,518 CVEs
CVE-2026-34091 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD
CVE-2026-34090 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2.

Vendor: Wikimedia Foundation
Product: CheckUser
Published: May 11, 2026
Source: NVD
CVE-2026-34088 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD
CVE-2026-34087 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: OATHAuth
Published: May 11, 2026
Source: NVD
CVE-2026-31247 HIGH - 7.5

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML file containing a nested entity expansion payload (XML Bomb). When processed b...

Published: May 11, 2026
Source: NVD
CVE-2025-65418 HIGH - 7.5

docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.

Published: May 11, 2026
Source: NVD
CVE-2025-61314 HIGH - 7.3

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable val...

Published: May 11, 2026
Source: NVD
CVE-2025-61313 HIGH - 7.3

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable...

Published: May 11, 2026
Source: NVD
CVE-2025-61312 HIGH - 7.3

A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable valu...

Published: May 11, 2026
Source: NVD
CVE-2025-61311 HIGH - 7.3

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value...

Published: May 11, 2026
Source: NVD

GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent perfo...

Vendor: npm
Product: @github/copilot
Published: May 11, 2026
Source: GitHub
CVE-2026-44543 HIGH - 8.7

Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-pat...

Vendor: go
Product: github.com/rancher/local-path-provisioner
Published: May 11, 2026
Source: GitHub
CVE-2026-44521 HIGH - 8.8

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to ...

Vendor: composer
Product: studio-42/elfinder
Published: May 11, 2026
Source: GitHub
CVE-2026-44516 HIGH - 7.6

Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs the full request body, response body, and response headers...

Vendor: maven
Product: com.ritense.valtimo:web
Published: May 11, 2026
Source: GitHub
CVE-2026-44483 HIGH - 8.2

RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when wal...

Vendor: npm
Product: @rvf/set-get
Published: May 11, 2026
Source: GitHub
CVE-2026-44579 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurati...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44578 HIGH - 8.6

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server t...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44575 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetchin...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44574 HIGH - 8.1

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44573 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub