Total CVEs

138,574

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,049
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,341 - 4,360 of 12,537 CVEs
CVE-2026-41904 HIGH - 7.6

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply message. The payload is rendered unescaped in the auto-reply email sent to every customer who co...

Vendor: freescout-help-desk
Product: freescout
Published: May 07, 2026
Source: NVD
CVE-2026-7413 HIGH - 7.2

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cannot be disabled via user-facing settings, and survives factory reset and ordinary firmware updates.

Vendor: yarbo
Product: lawn_mower_firmware
Published: May 07, 2026
Source: NVD

Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause the victim's client to send their Matrix access token to an attacker-controlled server. This occurs when the victi...

Vendor: npm
Product: cinny
Published: May 07, 2026
Source: GitHub
CVE-2026-7821 HIGH - 7.4

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of th...

Vendor: ivanti
Product: endpoint_manager_mobile
Published: May 07, 2026
Source: NVD
CVE-2026-6973 HIGH - 7.2

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

Vendor: ivanti
Product: endpoint_manager_mobile
Published: May 07, 2026
Source: NVD
CVE-2026-5788 HIGH - 7.0

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

Vendor: ivanti
Product: endpoint_manager_mobile
Published: May 07, 2026
Source: NVD
CVE-2026-5787 HIGH - 8.9

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

Vendor: ivanti
Product: endpoint_manager_mobile
Published: May 07, 2026
Source: NVD
CVE-2026-5786 HIGH - 8.8

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

Vendor: ivanti
Product: endpoint_manager_mobile
Published: May 07, 2026
Source: NVD
CVE-2025-65122 HIGH - 7.5

Regex Denial of Service in youtube-regex npm package through version 1.0.5.

Published: May 07, 2026
Source: NVD
CVE-2026-42011 HIGH - 7.4

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validati...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 07, 2026
Source: NVD
CVE-2026-41688 HIGH - 7.7

Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS...

Vendor: ellite
Product: Wallos
Published: May 07, 2026
Source: NVD
CVE-2026-41505 HIGH - 8.7

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16.

Vendor: inducer
Product: relate
Published: May 07, 2026
Source: NVD
CVE-2025-63705 HIGH - 8.8

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.

Published: May 07, 2026
Source: NVD
CVE-2026-41554 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS. This issue affects Bricks Builder: from n/a through 1.9.2 to 2.2.

Vendor: Bricks
Product: Bricks Builder
Published: May 07, 2026
Source: NVD
CVE-2026-41490 HIGH - 8.3

Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster Core version 1.13.1 and prior to Dagster libraries version 0.29.1, the DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers constructed SQL WHERE clauses by interpolating dynamic...

Vendor: dagster-io
Product: dagster
Published: May 07, 2026
Source: NVD
CVE-2026-30495 HIGH - 8.8

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is configured with ro.adb.secure=0, which disables RSA key verification. Additionally, a functional su bina...

Published: May 07, 2026
Source: NVD
CVE-2025-14341 HIGH - 8.3

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from 4.8.2.19 before 4.8.3....

Vendor: DivvyDrive Information Technologies Inc.
Product: DivvyDrive
Published: May 07, 2026
Source: NVD
CVE-2026-8093 HIGH - 7.5

Memory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.

Vendor: mozilla
Product: firefox
Published: May 07, 2026
Source: NVD
CVE-2026-8092 HIGH - 8.1

Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 1...

Vendor: mozilla
Product: firefox
Published: May 07, 2026
Source: NVD
CVE-2026-8090 HIGH - 7.3

Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

Vendor: mozilla
Product: firefox
Published: May 07, 2026
Source: NVD