Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,287
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 401 - 420 of 3,184 CVEs
CVE-2026-47208 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47131 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError con...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-45663 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly in...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-44962 CRITICAL - 9.9

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the serve...

Vendor: WebPros
Product: Plesk
Published: May 29, 2026
Source: NVD
CVE-2026-4290 CRITICAL - 9.1

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete(...

Published: May 29, 2026
Source: NVD
CVE-2026-10042 CRITICAL - 9.8

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name} endpoints deserialize attacker-controlled HTTP request...

Vendor: zyddnys
Product: manga-image-translator
Published: May 29, 2026
Source: NVD
CVE-2026-46376 CRITICAL - 9.8

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP ...

Vendor: FreePBX
Product: security-reporting
Published: May 29, 2026
Source: NVD
CVE-2026-45312 CRITICAL - 9.9

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas wor...

Vendor: infiniflow
Product: ragflow
Published: May 29, 2026
Source: NVD
CVE-2026-10071 CRITICAL - 9.8

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Vendor: Interinfo
Product: DreamMaker
Published: May 29, 2026
Source: NVD
CVE-2026-9559 CRITICAL - 9.9

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (campaign...

Published: May 29, 2026
Source: NVD
CVE-2025-41277 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41276 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41275 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41274 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41273 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41272 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41270 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41269 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41268 CRITICAL - 9.1

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2026-9558 CRITICAL - 9.9

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the ...

Published: May 29, 2026
Source: NVD