Total CVEs

132,371

Critical Severity

2,837

High Severity

10,154

Last 7 Days

1,773
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,181 - 4,200 of 28,776 CVEs
CVE-2025-61306 MEDIUM - 6.1

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variab...

Published: May 11, 2026
Source: NVD
CVE-2025-61305 MEDIUM - 6.1

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable val...

Published: May 11, 2026
Source: NVD

GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent perfo...

Vendor: npm
Product: @github/copilot
Published: May 11, 2026
Source: GitHub
CVE-2026-44543 HIGH - 8.7

Local Path Provisioner Vulnerable to HelperPod Template Injection

Vendor: go
Product: github.com/rancher/local-path-provisioner
Published: May 11, 2026
Source: GitHub

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the ...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44521 HIGH - 8.8

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to ...

Vendor: composer
Product: studio-42/elfinder
Published: May 11, 2026
Source: GitHub
CVE-2026-44516 HIGH - 7.6

Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs the full request body, response body, and response headers...

Vendor: maven
Product: com.ritense.valtimo:web
Published: May 11, 2026
Source: GitHub
CVE-2026-44483 HIGH - 8.2

RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when wal...

Vendor: npm
Product: @rvf/set-get
Published: May 11, 2026
Source: GitHub

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

Vendor: go
Product: github.com/cloudnative-pg/cloudnative-pg
Published: May 11, 2026
Source: GitHub
CVE-2026-44581 MEDIUM - 4.7

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived f...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub

Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44580 MEDIUM - 6.1

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped ...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44579 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurati...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44577 MEDIUM - 5.9

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cau...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44578 HIGH - 8.6

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server t...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44576 MEDIUM - 5.4

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44575 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetchin...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44574 HIGH - 8.1

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub
CVE-2026-44573 HIGH - 7.5

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<...

Vendor: npm
Product: next
Published: May 11, 2026
Source: GitHub

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 ยง6.9.5.1 โ€” it could send a NAS Security Mode Command while an N2 handover was still pending (and vice versa). Concurre...

Vendor: go
Product: github.com/ellanetworks/core
Published: May 11, 2026
Source: GitHub