Total CVEs

132,383

Critical Severity

2,838

High Severity

10,163

Last 7 Days

1,716
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 4,481 - 4,500 of 28,788 CVEs

Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing unauthorized actions like system registration, plugin management, and configuration changes. This issue...

Vendor: emlog
Product: emlog
Published: May 08, 2026
Source: NVD

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, the inc "filename" directive in GPPL postprocessor files is resolved by GpplDocumentLinkHandler into a clickable link (VS Code textDocument/doc...

Vendor: anzory
Product: SolidCAM-GPPL-IDE
Published: May 08, 2026
Source: NVD

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor IDE extension causes the language server to parse a companion .vmid file from the same directory (namin...

Vendor: anzory
Product: SolidCAM-GPPL-IDE
Published: May 08, 2026
Source: NVD
CVE-2026-42209 MEDIUM - 6.5

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both set_retained_message_defer_timeout and set_retained_message_defer_timeout_spread are configured to non-default values...

Vendor: halfgaar
Product: FlashMQ
Published: May 08, 2026
Source: NVD
CVE-2026-42205 HIGH - 8.8

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to insecure action lookup logic, an authenticated user can execute any Action class (descendants of Avo::...

Vendor: avo-hq
Product: avo
Published: May 08, 2026
Source: NVD
CVE-2026-42202 MEDIUM - 6.5

nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard> middleware. Any user authenticated on the configured guard could call the endpoint and flip bo...

Vendor: almirhodzic
Product: nova-toggle-5
Published: May 08, 2026
Source: NVD
CVE-2026-42199 MEDIUM - 6.2

Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relationship between the grid’s logical dimensions and its backing storage. After the internal invariant is broken, the safe API get() may invoke get_unchec...

Vendor: becheran
Product: grid
Published: May 08, 2026
Source: NVD

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAuth sign-in. A crafted link causes the user's click on draw.io's "Authorize in GitLab&qu...

Vendor: jgraph
Product: drawio
Published: May 08, 2026
Source: NVD
CVE-2026-42193 CRITICAL - 9.1

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verifying the SNS signature, certificate, or topic ARN, meaning anyone can forge a valid-looking webhook r...

Vendor: useplunk
Product: plunk
Published: May 08, 2026
Source: NVD
CVE-2026-42192 MEDIUM - 5.4

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email body content created by authenticated project members is stored and later rendered in the admin dashboa...

Vendor: useplunk
Product: plunk
Published: May 08, 2026
Source: NVD

Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in version 2.6.11.

Vendor: emlog
Product: emlog
Published: May 08, 2026
Source: NVD
CVE-2026-44400 HIGH - 8.1

MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMai...

Vendor: MailEnable
Product: MailEnable Enterprise Premium
Published: May 08, 2026
Source: NVD
CVE-2026-44214 MEDIUM - 5.8

eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events...

Vendor: npm
Product: eventsource-encoder
Published: May 08, 2026
Source: GitHub
CVE-2026-44213 MEDIUM - 6.5

The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the INSTANA_ENDPOINT_P...

Vendor: nuget
Product: OpenTelemetry.Exporter.Instana
Published: May 08, 2026
Source: GitHub
CVE-2026-44247 MEDIUM - 6.8

Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluster pod that can reach the webhook endpoint may send an arbitrarily large request body, potentially cau...

Vendor: go
Product: volcano.sh/volcano
Published: May 08, 2026
Source: GitHub
CVE-2026-44211 CRITICAL - 9.6

Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability

Vendor: npm
Product: cline
Published: May 08, 2026
Source: GitHub
CVE-2026-44209 HIGH - 7.5

Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to Server-Side Template Inject...

Vendor: pip
Product: banks
Published: May 08, 2026
Source: GitHub
CVE-2026-44728 HIGH - 8.2

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-...

Vendor: npm
Product: @babel/plugin-transform-modules-systemjs
Published: May 08, 2026
Source: GitHub
CVE-2026-44200 MEDIUM - 6.5

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and potentially publish ...

Vendor: pip
Product: wagtail
Published: May 08, 2026
Source: GitHub
CVE-2026-44201 MEDIUM - 5.3

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulner...

Vendor: pip
Product: wagtail
Published: May 08, 2026
Source: GitHub