Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,235
Quick preset (or use dates below)
Clear Filters
Showing 4,181 - 4,200 of 13,084 CVEs
CVE-2026-44291 HIGH - 8.1

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables...

Vendor: npm
Product: protobufjs
Published: May 12, 2026
Source: GitHub
CVE-2026-44290 HIGH - 7.5

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write ...

Vendor: npm
Product: protobufjs
Published: May 12, 2026
Source: GitHub
CVE-2026-44289 HIGH - 7.5

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf ...

Vendor: npm
Product: protobufjs
Published: May 12, 2026
Source: GitHub
CVE-2026-42290 HIGH - 7.8

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead...

Vendor: npm
Product: protobufjs-cli
Published: May 12, 2026
Source: GitHub
CVE-2026-8390 HIGH - 7.3

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.

Vendor: mozilla
Product: firefox
Published: May 12, 2026
Source: NVD
CVE-2026-8389 HIGH - 7.3

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

Vendor: mozilla
Product: firefox
Published: May 12, 2026
Source: NVD
CVE-2026-35071 HIGH - 8.2

Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execu...

Vendor: Dell
Product: PowerScale InsightIQ
Published: May 12, 2026
Source: NVD
CVE-2026-27851 HIGH - 7.4

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No pub...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: May 12, 2026
Source: NVD
CVE-2026-45218 HIGH - 7.7

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a through <= 11.4.0.

Vendor: WP Travel
Product: WP Travel
Published: May 12, 2026
Source: NVD
CVE-2026-45214 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through <= 1.5.1.

Vendor: Xpro
Product: Xpro Elementor Addons
Published: May 12, 2026
Source: NVD
CVE-2026-45213 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1.

Vendor: RealMag777
Product: BEAR
Published: May 12, 2026
Source: NVD
CVE-2026-45211 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.1.

Vendor: Saad Iqbal
Product: APIExperts Square for WooCommerce
Published: May 12, 2026
Source: NVD
CVE-2026-42742 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6.

Vendor: Aman
Product: Views for WPForms
Published: May 12, 2026
Source: NVD
CVE-2026-42741 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms View...

Vendor: Aman
Product: Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend
Published: May 12, 2026
Source: NVD
CVE-2026-41713 HIGH - 8.2

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.

Vendor: VMware
Product: Spring AI
Published: May 12, 2026
Source: NVD
CVE-2026-41712 HIGH - 7.5

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

Vendor: VMware
Product: Spring AI
Published: May 12, 2026
Source: NVD
CVE-2026-2465 HIGH - 8.8

Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026.

Published: May 12, 2026
Source: NVD
CVE-2026-8162 HIGH - 7.5

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value without try/catch. The...

Vendor: pillarjs
Product: multiparty
Published: May 12, 2026
Source: NVD
CVE-2026-8161 HIGH - 7.5

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.prototype property such as __proto__, constructor, or toString, the parser invokes .push() on the inherite...

Vendor: pillarjs
Product: multiparty
Published: May 12, 2026
Source: NVD
CVE-2026-8159 HIGH - 7.5

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a long header value can cause regex matching to take seconds, blocking the event loop. Impact: any service...

Vendor: pillarjs
Product: multiparty
Published: May 12, 2026
Source: NVD