Total CVEs

139,961

Critical Severity

3,664

High Severity

13,210

Last 7 Days

1,617
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,421 - 4,440 of 13,369 CVEs
CVE-2026-44425 MEDIUM - 5.4

ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in the base64-encoded filter query parameter and the sort_by query parameter, which are then passed directly as BSON/SQL keys in the data...

Vendor: go
Product: github.com/shellhub-io/shellhub
Published: May 06, 2026
Source: GitHub
CVE-2026-44423 MEDIUM - 6.5

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any authenticated caller, without scoping by the caller's tenant. An authenticated user can read session records (SSH username, device UID, remote IP, terminal type, authenticated ...

Vendor: go
Product: github.com/shellhub-io/shellhub
Published: May 06, 2026
Source: GitHub
CVE-2026-44424 MEDIUM - 6.5

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever the caller is authenticated, without verifying that the device belongs to the caller's namespace (tenant). Any authenticated user (JWT or API Key) who knows or can guess a devic...

Vendor: go
Product: github.com/shellhub-io/shellhub
Published: May 06, 2026
Source: GitHub
CVE-2026-44374 MEDIUM - 4.3

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of o...

Vendor: npm
Product: @backstage/plugin-catalog-unprocessed-entities-common
Published: May 06, 2026
Source: GitHub

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. This vulnerability is fixed in 3.0.260429-beta.

Vendor: npm
Product: nitro
Published: May 06, 2026
Source: GitHub
CVE-2026-44373 MEDIUM - 5.3

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3....

Vendor: npm
Product: nitro
Published: May 06, 2026
Source: GitHub

PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secre...

Vendor: pip
Product: pyquorum
Published: May 06, 2026
Source: GitHub

MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could all...

Vendor: pip
Product: misp-modules
Published: May 06, 2026
Source: GitHub
CVE-2026-3291 MEDIUM - 5.5

Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.

Vendor: hp
Product: samsung_print_service_plugin
Published: May 06, 2026
Source: NVD
CVE-2026-44245 MEDIUM - 6.1

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue compone...

Vendor: go
Product: github.com/kyverno/policy-reporter-ui
Published: May 06, 2026
Source: GitHub
CVE-2026-42572 MEDIUM - 5.3

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization directive on the GET /api/v1/stable/dags/tasks endpoint caused Hatchet's tenant-membership check to be skipped for this route. A user authenticated to a...

Vendor: go
Product: github.com/hatchet-dev/hatchet
Published: May 06, 2026
Source: GitHub
CVE-2026-44223 MEDIUM - 6.5

vLLM is an inference and serving engine for large language models (LLMs). From to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a RuntimeError that crashes the EngineCore process. The cras...

Vendor: pip
Product: vllm
Published: May 06, 2026
Source: GitHub
CVE-2026-42549 MEDIUM - 4.4

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recursive: true) on a path built from the user-supplied controller name, before Nette's class-name validation runs. The class-file write is correctly rejected by Nette when the nam...

Vendor: composer
Product: flightphp/core
Published: May 06, 2026
Source: GitHub
CVE-2026-42545 MEDIUM - 5.9

Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses .unwrap() on both the header name and header value constructors, so malforme...

Vendor: pip
Product: granian
Published: May 06, 2026
Source: GitHub

Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools without restrictions on file system access. As a result, executing hugo against an untrusted site could a...

Vendor: go
Product: github.com/gohugoio/hugo
Published: May 06, 2026
Source: GitHub

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -> System -> Import/Ex...

Vendor: composer
Product: openmage/magento-lts
Published: May 06, 2026
Source: GitHub
CVE-2026-44306 MEDIUM - 5.3

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed for a given email address. An unauthenticated attacker could use this to enumerate valid users, which can aid in follow-up...

Vendor: composer
Product: statamic/cms
Published: May 06, 2026
Source: GitHub
CVE-2026-8033 MEDIUM - 5.3

A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ of the component Response Header Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. The exploit has b...

Published: May 06, 2026
Source: NVD
CVE-2026-44117 MEDIUM - 5.8

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMedia endpoints to relay unintended requests.

Vendor: OpenClaw
Product: OpenClaw
Published: May 06, 2026
Source: NVD
CVE-2026-44113 MEDIUM - 5.3

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and access unauthorize...

Vendor: OpenClaw
Product: OpenClaw
Published: May 06, 2026
Source: NVD