Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

1,999
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,181 - 4,200 of 12,518 CVEs
CVE-2026-29203 HIGH - 8.8

A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova pat...

Vendor: WebPros
Product: cPanel, cPanel (CentOS 6, CloudLinux 6), WP Squared
Published: May 08, 2026
Source: NVD
CVE-2026-29202 HIGH - 8.8

Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.

Vendor: WebPros
Product: cPanel, cPanel (CentOS 6, CloudLinux 6), WP Sqaured
Published: May 08, 2026
Source: NVD
CVE-2026-44721 HIGH - 7.3

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a stored cross-site scripting (XSS) vulnerability that allows any authenticated user with model creation permission (workspace.models) to execute arbitrary JavaScript in the browser of ...

Vendor: npm
Product: open-webui
Published: May 08, 2026
Source: GitHub
CVE-2026-6659 HIGH - 7.5

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

Published: May 08, 2026
Source: NVD
CVE-2026-44714 HIGH - 7.5

The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends() contains two fast-path verification bugs for standard P2PKH and native P2WPKH spends in core/src/main/java/org/bitcoinj/script/ScriptExecution.java. In both branches, bitcoinj ve...

Vendor: maven
Product: org.bitcoinj:bitcoinj-core
Published: May 08, 2026
Source: GitHub
CVE-2026-44671 HIGH - 7.5

ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorporating them into LDAP search filters. This al...

Vendor: go
Product: github.com/zitadel/zitadel
Published: May 08, 2026
Source: GitHub

Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception ...

Vendor: erlang
Product: ex_webrtc
Published: May 08, 2026
Source: GitHub
CVE-2026-44694 HIGH - 9.1

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before version 2.50.2, there is an authenticated server-side request forgery vulnerability affecting the webhook trigger tools, the n8n API client (N8N_API_URL), ...

Vendor: npm
Product: n8n-mcp
Published: May 08, 2026
Source: GitHub
CVE-2026-44665 HIGH - 6.1

fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability ...

Vendor: npm
Product: fast-xml-builder
Published: May 08, 2026
Source: GitHub

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent...

Vendor: ZcashFoundation
Product: zebra
Published: May 08, 2026
Source: NVD

Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via quadratic fragment-name uniqueness validation. 'Elixir.Absinthe.Phase.Document.Validation.UniqueFragmentNames':run/2 iterates over all fragments and for each one call...

Vendor: absinthe-graphql
Product: absinthe
Published: May 08, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom table exhaustion when parsing attacker-controlled GraphQL SDL. Multiple Blueprint.Draft.convert/2 implementations in Absinthe's SDL language modules...

Vendor: absinthe-graphql
Product: absinthe
Published: May 08, 2026
Source: NVD
CVE-2026-41886 HIGH - 7.5

locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK registers a window.addEventListener("message", โ€ฆ) handler that dispatches to registered internal handlers (editKey, commitKey, commitKeys, isLocizeEnabled, requestInitialize,...

Vendor: locize
Product: locize
Published: May 08, 2026
Source: NVD
CVE-2026-41883 HIGH - 8.1

OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:*=https://cdn.example...

Vendor: omnifaces
Product: omnifaces
Published: May 08, 2026
Source: NVD
CVE-2026-41693 HIGH - 8.2

i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options directly into the configured loadPath / addPath templates and then read / write the resulting file f...

Vendor: i18next
Product: i18next-fs-backend
Published: May 08, 2026
Source: NVD
CVE-2026-41690 HIGH - 8.6

18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach...

Vendor: i18next
Product: i18next-http-middleware
Published: May 08, 2026
Source: NVD
CVE-2026-34354 HIGH - 7.4

Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the Handl...

Vendor: Akamai
Product: Guardicore Platform Agent, Zero Trust Client
Published: May 08, 2026
Source: NVD
CVE-2026-29975 HIGH - 7.5

lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic incorrectly identifies escaped quote characters by only checking the immediately preceding character rather than counting consecutive backslashes, causin...

Published: May 08, 2026
Source: NVD
CVE-2026-29974 HIGH - 7.5

An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a caller-provided buffer without a size parameter. Applications using minmea_scan on untrusted input are vulnerable to a stack buffer overflow.

Published: May 08, 2026
Source: NVD
CVE-2026-29972 HIGH - 8.2

nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the library writes register data from the server response to the caller-provided buffer based on the response&#...

Published: May 08, 2026
Source: NVD