Total CVEs

138,574

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,049
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,361 - 4,380 of 12,537 CVEs
CVE-2026-6002 HIGH - 8.8

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

Published: May 07, 2026
Source: NVD
CVE-2026-5784 HIGH - 8.8

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

Published: May 07, 2026
Source: NVD
CVE-2026-42010 HIGH - 7.1

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. Th...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 07, 2026
Source: NVD
CVE-2026-3953 HIGH - 8.8

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XSS), Reflected XSS. This issue affects Proticaret E-Commerce: from v5.0.0 before V 6.0.1767...

Published: May 07, 2026
Source: NVD
CVE-2026-33588 HIGH - 8.1

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.

Vendor: Open Notebook
Product: Open Notebook
Published: May 07, 2026
Source: NVD
CVE-2026-28201 HIGH - 7.8

An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is a...

Vendor: Open Notebook
Product: Open Notebook
Published: May 07, 2026
Source: NVD
CVE-2026-6805 HIGH - 7.5

Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force attack of the access code associated to this sharing link.

Vendor: thalesgroup
Product: ercom_cryptobox
Published: May 07, 2026
Source: NVD
CVE-2025-68060 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection. This issue affects Team Member: from n/a through 8.5.

Vendor: WPMart
Product: Team Member
Published: May 07, 2026
Source: NVD
CVE-2025-1978 HIGH - 8.3

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual St...

Vendor: hitachi
Product: virtual_storage_one_block
Published: May 07, 2026
Source: NVD
CVE-2024-43384 HIGH - 8.0

A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

Vendor: phoenixcontact
Product: fl_mguard_2102_firmware
Published: May 07, 2026
Source: NVD
CVE-2026-4430 HIGH - 7.8

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

Vendor: libreoffice
Product: libreoffice
Published: May 07, 2026
Source: NVD
CVE-2025-9661 HIGH - 8.1

OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

Vendor: hitachi
Product: virtual_storage_one_block
Published: May 07, 2026
Source: NVD
CVE-2026-7252 HIGH - 8.1

The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, ...

Published: May 07, 2026
Source: NVD
CVE-2026-6692 HIGH - 8.8

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subsc...

Published: May 07, 2026
Source: NVD
CVE-2026-4348 HIGH - 7.5

The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in all versions up to, and including, 3.7.0. This is due to the `limit` POST parameter being interpolated directly into a SQL query string before being pass...

Published: May 07, 2026
Source: NVD
CVE-2026-41143 HIGH - 8.8

YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerability in tools/bazar/services/EntryManager.php at line 704. The $data['id_fiche'] value (sourced from $_POST['id_fiche']) is concatenated directly into a raw SQL...

Vendor: YesWiki
Product: yeswiki
Published: May 07, 2026
Source: NVD
CVE-2026-41139 HIGH - 8.8

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

Vendor: josdejong
Product: mathjs
Published: May 07, 2026
Source: NVD
CVE-2026-44513 HIGH - 8.8

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three va...

Vendor: pip
Product: diffusers
Published: May 07, 2026
Source: GitHub
CVE-2026-43998 HIGH - 8.5

vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses path.resolve() (which does not...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-44004 HIGH - 7.5

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a synchronous C++ native call, vm2's timeout option cannot interrupt it. A single request can exhaus...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub