Total CVEs

139,961

Critical Severity

3,664

High Severity

13,210

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,381 - 4,400 of 13,369 CVEs
CVE-2025-68604 MEDIUM - 5.4

Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGraphQL: from n/a through 2.5.3.

Vendor: WPGraphQL
Product: WPGraphQL
Published: May 07, 2026
Source: NVD
CVE-2025-66105 MEDIUM - 5.3

Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8.

Vendor: Magepeople inc.
Product: Bus Ticket Booking with Seat Reservation
Published: May 07, 2026
Source: NVD
CVE-2025-62127 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS. This issue affects WEN Logo Slider: from n/a through 3.4.0.

Vendor: WEN Themes
Product: WEN Logo Slider
Published: May 07, 2026
Source: NVD
CVE-2025-2514 MEDIUM - 5.3

Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Bl...

Vendor: hitachi
Product: virtual_storage_one_block
Published: May 07, 2026
Source: NVD
CVE-2026-44406 MEDIUM - 5.7

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServic...

Vendor: ZTE
Product: ZXCLOUD iRAI
Published: May 07, 2026
Source: NVD
CVE-2026-8063 MEDIUM - 6.5

An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggregation pipeline to determine whether it begins with an Atlas Search stage. For $rankFusion and $scoreFusion, this inspection reads th...

Vendor: mongodb
Product: mongodb
Published: May 07, 2026
Source: NVD
CVE-2026-41413 MEDIUM - 5.0

Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a jwksUri pointing to an internal service, istiod makes an unauthenticated HTTP GET request to that URL without filtering out localhost o...

Vendor: istio
Product: istio
Published: May 07, 2026
Source: NVD
CVE-2026-44248 MEDIUM - 5.3

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the by...

Vendor: maven
Product: io.netty:netty-codec-mqtt
Published: May 07, 2026
Source: GitHub
CVE-2026-44003 MEDIUM - 5.3

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain catch, import, or async keywords. This fast-path bypass allows sandboxed code to directly access the internal VM2_INTERNAL_...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-44002 MEDIUM - 5.8

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandb...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-44000 MEDIUM - 6.5

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sand...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-6214 MEDIUM - 6.5

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capability check before saving the scheduled export configuration,...

Published: May 07, 2026
Source: NVD
CVE-2026-41004 MEDIUM - 4.4

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 thro...

Vendor: Spring
Product: Spring Cloud Config
Published: May 07, 2026
Source: NVD
CVE-2026-40004 MEDIUM - 5.5

There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.

Vendor: ZTE
Product: ZXCLOUD iRAI
Published: May 07, 2026
Source: NVD

gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted by the current set of root keys. gittuf determines the policy to load by inspecting the RSL. Exc...

Vendor: go
Product: github.com/gittuf/gittuf
Published: May 07, 2026
Source: GitHub
CVE-2026-4807 MEDIUM - 6.5

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin expos...

Published: May 07, 2026
Source: NVD
CVE-2026-44520 MEDIUM - 5.7

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to 1.5.1, the URLInputHandler class in docling_graph/core/input/handlers.py makes HTTP requests to user-supplied URLs without validating whether the targe...

Vendor: pip
Product: docling-graph
Published: May 07, 2026
Source: GitHub
CVE-2026-44426 MEDIUM - 6.5

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — including the members list (user IDs, e-mails, roles), settings, and device counts — to any caller authenticated by an API Key, for any tenant, regardless of the API Key's own...

Vendor: go
Product: github.com/shellhub-io/shellhub
Published: May 07, 2026
Source: GitHub
CVE-2026-44514 MEDIUM - 6.5

Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to ...

Vendor: go
Product: github.com/kubetail-org/kubetail/modules/dashboard
Published: May 07, 2026
Source: GitHub
CVE-2026-6222 MEDIUM - 5.3

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive module-management acti...

Published: May 07, 2026
Source: NVD