Total CVEs

138,574

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,055
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,301 - 4,320 of 12,537 CVEs
CVE-2026-8132 HIGH - 7.3

A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be u...

Published: May 08, 2026
Source: NVD
CVE-2026-8131 HIGH - 7.3

A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the argument msgid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public ...

Published: May 08, 2026
Source: NVD
CVE-2026-8130 HIGH - 7.3

A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be us...

Published: May 08, 2026
Source: NVD
CVE-2026-8129 HIGH - 7.3

A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of the argument delwlistid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclo...

Published: May 08, 2026
Source: NVD
CVE-2026-43943 HIGH - 7.8

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code execution (RCE) vulnerability exists in electerm's SFTP open with system editor or "Edit with custom editor" feature. When a user opts to edit a file using open wit...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-43940 HIGH - 8.4

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating userโ€‘supplied widget identifiers without any sanitisation. Because runWidget is...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-42275 HIGH - 8.7

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a l...

Vendor: openziti
Product: zrok
Published: May 08, 2026
Source: NVD
CVE-2026-42271 HIGH - 8.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it โ€” POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list โ€” accepted a full server configuration ...

Vendor: BerriAI
Product: litellm
Published: May 08, 2026
Source: NVD
CVE-2026-42261 HIGH - 7.1

PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills.ts exposes an authenticated endpoint POST /api/skills/fetch-remote that fetches a user-supplied URL server-side and reflects the response body (up to ...

Vendor: legeling
Product: PromptHub
Published: May 08, 2026
Source: NVD
CVE-2026-42203 HIGH - 8.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the Lit...

Vendor: BerriAI
Product: litellm
Published: May 08, 2026
Source: NVD
CVE-2026-8128 HIGH - 7.3

A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of the argument msgid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made publ...

Published: May 08, 2026
Source: NVD
CVE-2026-8126 HIGH - 7.3

A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Published: May 08, 2026
Source: NVD
CVE-2026-6411 HIGH - 7.3

This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Due to the presence of a hardcoded AES key within the application, the encrypted data can be decrypted, ena...

Published: May 07, 2026
Source: NVD
CVE-2026-7541 HIGH - 7.5

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies w...

Vendor: github
Product: enterprise_server
Published: May 07, 2026
Source: NVD
CVE-2026-41105 HIGH - 8.1

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_monitor_action_group_notification_system
Published: May 07, 2026
Source: NVD
CVE-2026-40213 HIGH - 7.4

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments c...

Vendor: OpenStack
Product: Cyborg
Published: May 07, 2026
Source: NVD
CVE-2026-35435 HIGH - 8.6

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_ai_foundry
Published: May 07, 2026
Source: NVD
CVE-2026-34327 HIGH - 8.2

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: partner_center
Published: May 07, 2026
Source: NVD
CVE-2026-33111 HIGH - 7.5

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: copilot_chat
Published: May 07, 2026
Source: NVD
CVE-2026-32207 HIGH - 8.8

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: azure_machine_learning
Published: May 07, 2026
Source: NVD