Total CVEs

132,371

Critical Severity

2,837

High Severity

10,154

Last 7 Days

1,783
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,141 - 4,160 of 28,776 CVEs
CVE-2026-45109 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-45061 HIGH - 7.7

Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) validates the submitted URL with a single substring check: url.includes(".tar.gz"). Any URL containing .tar.gz anywhere in the string — in the path, query string, or fragment —...

Vendor: npm
Product: budibase
Published: May 11, 2026
Source: GitHub
CVE-2026-45047 HIGH - 7.5

bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read size. An unauthenticated remote attacker can stream...

Vendor: go
Product: github.com/xddxdd/bird-lg-go
Published: May 11, 2026
Source: GitHub
CVE-2026-8292 MEDIUM - 4.3

A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in the library /lib/sbi/conv.c of the component NRF. Such manipulation of the argument hnrf-uri leads to denial of service. The attack may be performed from remote. The exploit has be...

Vendor: open5gs
Product: open5gs
Published: May 11, 2026
Source: NVD
CVE-2026-8291 MEDIUM - 4.3

A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the file lib/sbi/nnrf-handler.c of the component NRF. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been made available t...

Vendor: open5gs
Product: open5gs
Published: May 11, 2026
Source: NVD
CVE-2026-7820 MEDIUM - 6.5

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server...

Published: May 11, 2026
Source: NVD
CVE-2026-7819 HIGH - 8.1

Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside thei...

Published: May 11, 2026
Source: NVD
CVE-2026-7818 HIGH - 7.0

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any HMAC integrity check. Any file dropped into the sessions ...

Published: May 11, 2026
Source: NVD
CVE-2026-7817 MEDIUM - 6.5

Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read arbitrary server-side files...

Published: May 11, 2026
Source: NVD
CVE-2026-7816 HIGH - 8.8

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy metacommand template without sanitization. An authenticated user could inject ") TO PROGRAM 'cmd'" to break out of the \copy (...)...

Published: May 11, 2026
Source: NVD
CVE-2026-7815 HIGH - 8.8

SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespace) were concatenated directly into the rendered VACUUM/ANALYZE/REINDEX command and passed to psql --command. An authenticated user w...

Published: May 11, 2026
Source: NVD
CVE-2026-7814 MEDIUM - 4.8

Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML markup to execute atta...

Published: May 11, 2026
Source: NVD
CVE-2026-7813 CRITICAL - 9.9

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-owned objects without filtering by the requesting user's identity. An authenticated user could access another user&...

Published: May 11, 2026
Source: NVD
CVE-2026-6815 MEDIUM - 5.9

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesyste...

Published: May 11, 2026
Source: NVD

Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8.

Published: May 11, 2026
Source: NVD
CVE-2026-44643 CRITICAL - 10.0

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.

Vendor: peerigon
Product: angular-expressions
Published: May 11, 2026
Source: NVD

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.

Published: May 11, 2026
Source: NVD

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /collection/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.

Published: May 11, 2026
Source: NVD
CVE-2026-34092 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Skin/Skin.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD
CVE-2026-34091 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD