Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,008
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 4,101 - 4,120 of 12,518 CVEs
CVE-2026-44473 HIGH - 7.1

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-conne...

Vendor: go
Product: github.com/ellanetworks/core
Published: May 11, 2026
Source: GitHub
CVE-2026-45017 HIGH - 7.5

Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search paths when given an absolute path to resolve. This allows malicious template authors to load and render...

Vendor: pip
Product: python-liquid
Published: May 11, 2026
Source: GitHub
CVE-2026-44432 HIGH - 7.5

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.dra...

Vendor: pip
Product: urllib3
Published: May 11, 2026
Source: GitHub
CVE-2026-44431 HIGH - 5.3

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

Vendor: pip
Product: urllib3
Published: May 11, 2026
Source: GitHub

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose valu...

Vendor: go
Product: github.com/go-git/go-git/v6
Published: May 11, 2026
Source: GitHub
CVE-2026-44971 HIGH - 8.2

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an ...

Vendor: pip
Product: guarddog
Published: May 11, 2026
Source: GitHub
CVE-2026-44902 HIGH - 7.5

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid ...

Vendor: npm
Product: @opentelemetry/exporter-prometheus
Published: May 11, 2026
Source: GitHub
CVE-2026-44346 HIGH - 8.8

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injected value in envs[*].name produces unquoted RUN directives in the BentoML-generated Dockerfile. When the victim runs bentom...

Vendor: pip
Product: bentoml
Published: May 11, 2026
Source: GitHub
CVE-2026-44345 HIGH - 8.8

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 interpolates docker.base_image raw with no escaping, newline filtering, or validation. A malicious bent...

Vendor: pip
Product: bentoml
Published: May 11, 2026
Source: GitHub
CVE-2026-44570 HIGH - 8.3

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surrounding the memories API were inconsistent, resulting in the ability of a standard user to delete, restore, and view the contents of other users' memori...

Vendor: pip
Product: open-webui
Published: May 11, 2026
Source: GitHub
CVE-2026-4802 HIGH - 8.0

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substi...

Published: May 11, 2026
Source: NVD
CVE-2026-44985 HIGH - 9.6

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade requests from any origin. Combined with the JWT cookie using SameSite: Lax, this enables C...

Vendor: go
Product: github.com/amir20/dozzle
Published: May 11, 2026
Source: GitHub
CVE-2026-44569 HIGH - 7.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's an IDOR in the channels message management system that allows authenticated users to modify or delete any message within channels they have read access to. The vulnerabili...

Vendor: pip
Product: open-webui
Published: May 11, 2026
Source: GitHub
CVE-2026-44565 HIGH - 8.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names ...

Vendor: pip
Product: open-webui
Published: May 11, 2026
Source: GitHub
CVE-2026-42595 HIGH - 8.6

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:// URIs. An unauthenticated attacker can point...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 11, 2026
Source: GitHub
CVE-2025-10470 HIGH - 8.6

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that ut...

Vendor: WSO2
Product: WSO2 Identity Server, WSO2 Carbon MagicLink Authenticator Module
Published: May 11, 2026
Source: NVD
CVE-2026-41951 HIGH - 7.2

Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.

Vendor: GROWI, Inc.
Product: GROWI
Published: May 11, 2026
Source: NVD
CVE-2026-32658 HIGH - 8.0

Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: Automation Platform
Published: May 11, 2026
Source: NVD
CVE-2025-10908 HIGH - 7.3

Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that have been locked. This vulnerability may allow u...

Vendor: WSO2
Product: WSO2 Identity Server, WSO2 Carbon MagicLink Authenticator Module
Published: May 11, 2026
Source: NVD
CVE-2026-43500 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to a linear one before calling into the se...

Vendor: Linux
Product: Linux
Published: May 11, 2026
Source: NVD