Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

1,988
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,261 - 4,280 of 12,518 CVEs
CVE-2026-39816 HIGH - 8.8

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Scrip...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: May 08, 2026
Source: NVD
CVE-2025-66467 HIGH - 8.0

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access to it by using the previously generated...

Vendor: Apache Software Foundation
Product: Apache CloudStack
Published: May 08, 2026
Source: NVD
CVE-2022-50994 HIGH - 8.1

DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter. Attackers can exploit unsanitized...

Vendor: DrayTek
Product: Vigor 2960
Published: May 08, 2026
Source: NVD
CVE-2026-7330 HIGH - 7.2

The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escapin...

Published: May 08, 2026
Source: NVD
CVE-2026-5127 HIGH - 8.8

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files...

Published: May 08, 2026
Source: NVD
CVE-2026-43284 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-67888 HIGH - 7.3

An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated a...

Published: May 08, 2026
Source: NVD
CVE-2025-55449 HIGH - 7.3

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.

Vendor: astrbot
Product: astrbot
Published: May 08, 2026
Source: NVD
CVE-2024-53326 HIGH - 7.3

LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.

Published: May 08, 2026
Source: NVD
CVE-2024-46508 HIGH - 7.5

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

Vendor: yeti-platform
Product: yeti
Published: May 08, 2026
Source: NVD
CVE-2024-46507 HIGH - 7.3

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

Vendor: yeti-platform
Product: yeti
Published: May 08, 2026
Source: NVD
CVE-2024-45257 HIGH - 7.3

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

Published: May 08, 2026
Source: NVD
CVE-2024-33288 HIGH - 7.3

Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

Published: May 08, 2026
Source: NVD
CVE-2024-27686 HIGH - 7.5

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Published: May 08, 2026
Source: NVD
CVE-2026-8148 HIGH - 7.8

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

Vendor: navercorp
Product: mybox
Published: May 08, 2026
Source: NVD
CVE-2026-8138 HIGH - 8.8

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: tenda
Product: cx12l_firmware
Published: May 08, 2026
Source: NVD
CVE-2026-8137 HIGH - 8.8

A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclose...

Published: May 08, 2026
Source: NVD
CVE-2023-42346 HIGH - 7.5

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

Published: May 08, 2026
Source: NVD
CVE-2023-42344 HIGH - 7.3

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

Published: May 08, 2026
Source: NVD
CVE-2022-26522 HIGH - 7.8

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.

Published: May 08, 2026
Source: NVD