Total CVEs

133,212

Critical Severity

2,921

High Severity

10,625

Last 7 Days

2,058
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,241 - 4,260 of 29,617 CVEs
CVE-2026-44015 HIGH - 8.5

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forward...

Vendor: 0xJacky
Product: nginx-ui
Published: May 12, 2026
Source: NVD
CVE-2026-42855 HIGH - 7.5

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp32 computes the authentication hash using the URI field from the client's Authorization header, ...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-42854 CRITICAL - 9.8

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP heade...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-42268 HIGH - 7.5

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @veri...

Vendor: owasp-modsecurity
Product: ModSecurity
Published: May 12, 2026
Source: NVD
CVE-2026-41195 MEDIUM - 5.0

mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker-controlled URL that the server later fetches. Because the server follows http/https redirects and do...

Vendor: mosparo
Product: mosparo
Published: May 12, 2026
Source: NVD
CVE-2026-35555 MEDIUM - 6.3

PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2026-33570 MEDIUM - 5.7

PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020
Published: May 12, 2026
Source: NVD
CVE-2026-26289 HIGH - 8.2

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2026-44403 HIGH - 7.2

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session va...

Vendor: Wing FTP Server
Product: Wing FTP Server
Published: May 12, 2026
Source: NVD
CVE-2026-44246 HIGH - 7.2

nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable to Agentic Workflow Injection. The workflow sets allowed_non_write_users: ${{ github.event.issue.use...

Vendor: MIC-DKFZ
Product: nnUNet
Published: May 12, 2026
Source: NVD
CVE-2026-44224 HIGH - 8.8

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model witho...

Vendor: requarks
Product: wiki
Published: May 12, 2026
Source: NVD
CVE-2026-35504 MEDIUM - 5.5

PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2025-65088 HIGH - 7.8

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.

Vendor: Ashlar-Vellum
Product: Cobalt, Xenon, Argon, Lithium, Cobalt Share
Published: May 12, 2026
Source: NVD
CVE-2025-65087 HIGH - 7.8

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.

Vendor: Ashlar-Vellum
Product: Cobalt, Xenon, Argon, Lithium, Cobalt Share
Published: May 12, 2026
Source: NVD
CVE-2025-65086 HIGH - 7.8

An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary code when a specially crafted VC6 file is being parsed.

Vendor: Ashlar-Vellum
Product: Cobalt, Xenon, Argon, Lithium, Cobalt Share
Published: May 12, 2026
Source: NVD
CVE-2026-8052 MEDIUM - 6.0

HashiCorp Nomadโ€™s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.

Published: May 12, 2026
Source: NVD
CVE-2026-7474 HIGH - 8.8

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Published: May 12, 2026
Source: NVD
CVE-2026-6959 MEDIUM - 6.0

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Published: May 12, 2026
Source: NVD
CVE-2026-45185 CRITICAL - 9.8

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to hea...

Vendor: Exim
Product: Exim
Published: May 12, 2026
Source: NVD
CVE-2026-44874 MEDIUM - 4.9

A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of confidential system inform...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD