Total CVEs

133,212

Critical Severity

2,921

High Severity

10,625

Last 7 Days

2,054
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,221 - 4,240 of 29,617 CVEs
CVE-2026-1250 HIGH - 7.5

The Court Reservation โ€“ Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the โ€˜idโ€™ parameter in all versions up to, and including, 1.10.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...

Published: May 12, 2026
Source: NVD
CVE-2025-15463 MEDIUM - 6.5

The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes ...

Vendor: hwk-fr
Product: Advanced Custom Fields: Extended
Published: May 12, 2026
Source: NVD

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation...

Vendor: pip
Product: ujson
Published: May 12, 2026
Source: GitHub

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, corsProxyMiddleware forwards req.params.url directly into fetch(url, ...). It only blocks circular r...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code sends: res.status(500).send('Error occurred while trying to pr...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44650 CRITICAL - 9.1

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts extensionName: "." which bypasses sanitize-fi...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44649 CRITICAL - 9.8

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to auto...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44648 HIGH - 7.5

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authentication, storing all session data (user handle, perm...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44594 HIGH - 7.5

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in package.json. An attacker can publish an npm package that causes the server to read and return ...

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: May 12, 2026
Source: GitHub

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ultimately writes the data to storage via buildStorage.Put. The router concatenates the path components w...

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: May 12, 2026
Source: GitHub
CVE-2026-8449 HIGH - 8.8

Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subau...

Published: May 12, 2026
Source: NVD
CVE-2026-45227 HIGH - 8.8

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __impo...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45226 HIGH - 7.1

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds poin...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45225 HIGH - 7.6

Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted filename with traversal sequences. Attackers can exploit the unvalidated filename parameter in the u...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-44871 HIGH - 7.2

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying opera...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-44296 HIGH - 7.5

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and its first bytes do not parse as a valid TLS ClientH...

Vendor: deskflow
Product: deskflow
Published: May 12, 2026
Source: NVD
CVE-2026-44260 HIGH - 8.1

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no event handler c...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD
CVE-2026-44259 MEDIUM - 4.6

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security headers. Files with .html, .htm, or .svg extensions are served as text/html or image/svg+xml respectively,...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and home containment, but does not validate the dst (destination) parameter used by elfinder_paste. An attacker can copy or move files from within the home di...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and lands anywhere the Tomc...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD