Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,674
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,321 - 4,340 of 13,359 CVEs
CVE-2026-8115 MEDIUM - 5.3

A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the file src/server/routers/rest.ts of the component REST API. The manipulation of the argument req.params.tmpFile results in path traversal. The attack can be launched remotely. The expl...

Published: May 07, 2026
Source: NVD

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wr...

Vendor: rust
Product: openssl
Published: May 07, 2026
Source: GitHub
CVE-2026-44661 MEDIUM - 4.7

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. register_manual() validates the discovery URL against an HTTPS / l...

Vendor: pip
Product: utcp-http
Published: May 07, 2026
Source: GitHub
CVE-2026-8114 MEDIUM - 6.3

A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON Object Handler. The manipulation of the argument condition leads to sql injection. The attack can be initiated remotely. The exploit ...

Published: May 07, 2026
Source: NVD
CVE-2026-8113 MEDIUM - 4.3

A vulnerability was determined in 8421bit MiniClaw up to 43905b934cf76489ab28e4d17da28ee97970f91f. Affected by this vulnerability is the function isPathInside of the file src/kernel.ts of the component executeSkillScript. Executing a manipulation can lead to path traversal. It is possible to launch ...

Vendor: 8421bit
Product: miniclaw
Published: May 07, 2026
Source: NVD
CVE-2026-8112 MEDIUM - 6.3

A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the file src/kernel.ts. Performing a manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made...

Published: May 07, 2026
Source: NVD
CVE-2026-8106 MEDIUM - 6.1

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacke...

Vendor: github
Product: enterprise_server
Published: May 07, 2026
Source: NVD
CVE-2026-6736 MEDIUM - 6.5

An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When external authentication was enabled, the signup endpoint did not properly enforce the a...

Vendor: github
Product: enterprise_server
Published: May 07, 2026
Source: NVD
CVE-2026-41929 MEDIUM - 6.1

Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulating the r query parameter and _component_ajax POST parameter. Attackers can craft a malicious link or ...

Vendor: givanz
Product: Vvveb
Published: May 07, 2026
Source: NVD
CVE-2026-41928 MEDIUM - 5.3

Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated attackers to retrieve the application's secret cron key. Attackers can access the cron controller without authentication and retrieve the exposed secret key from the response...

Vendor: givanz
Product: Vvveb
Published: May 07, 2026
Source: NVD
CVE-2026-40214 MEDIUM - 6.3

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi ...

Vendor: OpenStack
Product: Cyborg
Published: May 07, 2026
Source: NVD
CVE-2026-8097 MEDIUM - 6.3

A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /askquery.php. The manipulation of the argument squeryx results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be...

Published: May 07, 2026
Source: NVD
CVE-2026-41692 MEDIUM - 4.7

i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens inside src and href attribute values with the raw string returned by i18next.t(). The substitution logic in src/loc...

Vendor: i18next
Product: i18nextify
Published: May 07, 2026
Source: NVD
CVE-2026-41691 MEDIUM - 6.5

Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3.0.5 interpolate the lng and ns values directly into the configured loadPath / addPath URL template w...

Vendor: i18next
Product: i18next-http-backend
Published: May 07, 2026
Source: NVD
CVE-2026-44500 MEDIUM - 5.3

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter prot...

Vendor: rust
Product: zebra-network
Published: May 07, 2026
Source: GitHub
CVE-2026-8142 MEDIUM - 6.5

VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.

Published: May 07, 2026
Source: NVD
CVE-2026-8087 MEDIUM - 5.3

A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldName results in heap-based buffer overflow. The attack must be initiated from a local position. The expl...

Vendor: osgeo
Product: gdal
Published: May 07, 2026
Source: NVD
CVE-2026-42241 MEDIUM - 5.3

ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.0.1, DecimalConverter.ReadDecimal makes a stackalloc using what might be an attacker-supplied value. If an attacker declares a decimal column with some unreasonable width, this cou...

Vendor: G-Research
Product: ParquetSharp
Published: May 07, 2026
Source: NVD
CVE-2026-42225 MEDIUM - 5.9

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_transport_tls) can accept connections with invalid or untrusted certificates even when the application explicitly enables certificate verification via ve...

Vendor: pjsip
Product: pjproject
Published: May 07, 2026
Source: NVD
CVE-2026-39826 MEDIUM - 6.1

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

Vendor: Go standard library
Product: html/template
Published: May 07, 2026
Source: NVD