Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,501 - 4,520 of 12,537 CVEs

Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checkin...

Vendor: composer
Product: craftcms/cms
Published: May 06, 2026
Source: GitHub

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled c...

Vendor: composer
Product: craftcms/cms
Published: May 06, 2026
Source: GitHub

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read eve...

Vendor: composer
Product: craftcms/cms
Published: May 06, 2026
Source: GitHub

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular...

Vendor: go
Product: github.com/QuantumNous/new-api
Published: May 06, 2026
Source: GitHub
CVE-2026-7875 HIGH - 8.8

NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container to read files outside the intended outbox directory by supplying crafted messages_out.id and content....

Published: May 06, 2026
Source: NVD
CVE-2026-42503 HIGH - 8.8

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0.  As a result, users might inadvertently cause gopls to bind 0.0.0.0. This c...

Vendor: golang.org/x/tools
Product: golang.org/x/tools/gopls
Published: May 06, 2026
Source: NVD
CVE-2026-23870 HIGH - 7.5

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react...

Vendor: Meta
Product: react-server-dom-turbopack, react-server-dom-parcel, react-server-dom-webpack
Published: May 06, 2026
Source: NVD
CVE-2026-20188 HIGH - 7.5

A vulnerability in the connection-handling mechanism of Cisco Crosswork Network Controller (CNC) and Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an inadeq...

Vendor: Cisco
Product: Cisco Crosswork Network Change Automation, Cisco Network Services Orchestrator
Published: May 06, 2026
Source: NVD
CVE-2026-20185 HIGH - 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on a...

Vendor: Cisco
Product: Cisco Small Business Smart and Managed Switches
Published: May 06, 2026
Source: NVD
CVE-2026-20167 HIGH - 7.7

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this v...

Vendor: Cisco
Product: Cisco IoT Field Network Director (IoT-FND)
Published: May 06, 2026
Source: NVD
CVE-2026-20035 HIGH - 7.2

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by ...

Vendor: Cisco
Product: Cisco Unity Connection
Published: May 06, 2026
Source: NVD
CVE-2026-20034 HIGH - 8.8

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability ...

Vendor: Cisco
Product: Cisco Unity Connection
Published: May 06, 2026
Source: NVD
CVE-2026-42283 HIGH - 7.7

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at th...

Vendor: go
Product: github.com/loft-sh/devspace
Published: May 06, 2026
Source: GitHub
CVE-2026-42280 HIGH - 7.1

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0.

Vendor: npm
Product: auth0-js
Published: May 06, 2026
Source: GitHub

Rejected reason: This CVE is a duplicate of another CVE: CVE-2026-33079.

Vendor: pip
Product: mistune
Published: May 06, 2026
Source: GitHub
CVE-2026-6788 HIGH - 7.8

Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.This issue affects WatchGuard Agent before 1.25.03.0000.

Vendor: watchguard
Product: agent
Published: May 06, 2026
Source: NVD
CVE-2026-6787 HIGH - 7.8

Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.This issue affects WatchGuard Agent: before 1.25.03.0000.

Vendor: watchguard
Product: agent
Published: May 06, 2026
Source: NVD
CVE-2026-6691 HIGH - 7.8

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAP...

Published: May 06, 2026
Source: NVD
CVE-2026-41288 HIGH - 7.8

Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.

Vendor: WatchGuard
Product: WatchGuard Agent
Published: May 06, 2026
Source: NVD
CVE-2026-40562 HIGH - 7.5

Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must ta...

Vendor: KAZEBURO
Product: Gazelle
Published: May 06, 2026
Source: NVD