Total CVEs

138,574

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,055
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,321 - 4,340 of 12,537 CVEs
CVE-2026-26164 HIGH - 7.5

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: 365_copilot_chat
Published: May 07, 2026
Source: NVD
CVE-2026-26129 HIGH - 7.5

Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: 365_copilot_chat
Published: May 07, 2026
Source: NVD
CVE-2026-44641 HIGH - 7.1

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.json into .apm/. The manifest fields agents, skills, commands, and hooks are attacker-controlled, but th...

Vendor: pip
Product: apm-cli
Published: May 07, 2026
Source: GitHub
CVE-2026-8098 HIGH - 7.3

A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly an...

Published: May 07, 2026
Source: NVD

Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, where the asset filename is provided through the X-Name HTTP request header. This value is stored dir...

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: May 07, 2026
Source: GitHub
CVE-2026-43510 HIGH - 7.6

manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.

Vendor: CISA
Product: manage.get.gov
Published: May 07, 2026
Source: NVD
CVE-2026-42501 HIGH - 7.5

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered vers...

Vendor: Go toolchain
Product: cmd/go
Published: May 07, 2026
Source: NVD
CVE-2026-42499 HIGH - 7.5

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

Vendor: Go standard library
Product: net/mail
Published: May 07, 2026
Source: NVD
CVE-2026-42239 HIGH - 8.1

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full acco...

Vendor: Budibase
Product: budibase
Published: May 07, 2026
Source: NVD
CVE-2026-39836 HIGH - 7.5

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

Vendor: Go standard library
Product: net
Published: May 07, 2026
Source: NVD
CVE-2026-39820 HIGH - 7.5

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Vendor: Go standard library
Product: net/mail
Published: May 07, 2026
Source: NVD
CVE-2026-33814 HIGH - 7.5

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

Vendor: golang.org/x/net, Go standard library
Product: golang.org/x/net/http2, net/http
Published: May 07, 2026
Source: NVD
CVE-2026-33811 HIGH - 7.5

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

Vendor: Go standard library
Product: net
Published: May 07, 2026
Source: NVD
CVE-2026-27891 HIGH - 7.2

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leadin...

Vendor: composer
Product: facturascripts/facturascripts
Published: May 07, 2026
Source: GitHub
CVE-2026-8083 HIGH - 7.3

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be u...

Published: May 07, 2026
Source: NVD
CVE-2026-44742 HIGH - 7.2

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

Vendor: Postorius project
Product: Postorius
Published: May 07, 2026
Source: NVD
CVE-2026-42215 HIGH - 8.8

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an appli...

Vendor: gitpython-developers
Product: GitPython
Published: May 07, 2026
Source: NVD
CVE-2026-42214 HIGH - 7.8

Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script without sanitization. An attacker can craft a filename whose extension contains Lua code, ...

Vendor: dail8859
Product: NotepadNext
Published: May 07, 2026
Source: NVD
CVE-2026-41906 HIGH - 7.1

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filtered search endpoint, but the backend conversation_change_customer action accepts any supplied cu...

Vendor: freescout-help-desk
Product: freescout
Published: May 07, 2026
Source: NVD
CVE-2026-41905 HIGH - 7.7

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but then re-validates the original URL instead of the final redirect destination....

Vendor: freescout-help-desk
Product: freescout
Published: May 07, 2026
Source: NVD