Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,709
Quick preset (or use dates below)
Clear Filters
Showing 4,541 - 4,560 of 13,312 CVEs
CVE-2026-42858 HIGH - 8.5

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed directly to requests.get() i...

Vendor: openedx
Product: openedx-platform
Published: May 11, 2026
Source: NVD
CVE-2026-41431 HIGH - 8.0

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signature...

Vendor: zen-browser
Product: desktop
Published: May 11, 2026
Source: NVD
CVE-2026-3609 HIGH - 7.8

Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cross reference to KVE 2023-5589 (https://krcert.or.kr)

Vendor: wellbia
Product: xigncode3
Published: May 11, 2026
Source: NVD
CVE-2026-38568 HIGH - 8.1

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve records by the user-supplied ID without verifying that the requesting user is the owner o...

Published: May 11, 2026
Source: NVD
CVE-2026-38566 HIGH - 8.1

HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission at /feedback/add/<id>, interview scheduling at /interviews/add) are vulnerable to CSRF. A...

Published: May 11, 2026
Source: NVD
CVE-2026-36983 HIGH - 7.3

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

Vendor: dlink
Product: dcs-932l_firmware
Published: May 11, 2026
Source: NVD
CVE-2026-36962 HIGH - 7.3

SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution by writing malicious files to the server's file system via the keyword parameter in the /index/...

Published: May 11, 2026
Source: NVD
CVE-2026-30635 HIGH - 8.1

Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/server.js when a user reads from an external FORGE_BASE_URL.

Published: May 11, 2026
Source: NVD
CVE-2026-2393 HIGH - 7.1

A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a user-controlled `url` parameter without validation, and the `_send_webhook_request()` function in `mlflow/webhooks/delivery.py` sends...

Published: May 11, 2026
Source: NVD
CVE-2026-2291 HIGH - 7.3

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

Published: May 11, 2026
Source: NVD
CVE-2026-44738 HIGH - 7.7

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration โ€” including all plugin secrets (SMTP passwords, AWS keys, OAuth client secrets...

Vendor: getgrav
Product: grav
Published: May 11, 2026
Source: NVD
CVE-2026-42603 HIGH - 8.8

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_target (privileged trigger) but checks out and executes code directly from the attacker's fork, en...

Vendor: OWASP-BLT
Product: BLT
Published: May 11, 2026
Source: NVD
CVE-2026-33362 HIGH - 8.6

In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service access keys.

Vendor: Meari
Product: com.meari.sdk
Published: May 11, 2026
Source: NVD
CVE-2026-33361 HIGH - 7.5

In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversible XOR over only the first 1024 bytes with a predictable key derivation model.

Vendor: Meari
Product: com.meari.sdk
Published: May 11, 2026
Source: NVD
CVE-2026-33359 HIGH - 7.5

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.

Vendor: Meari
Product: Alibaba OSS Hosted
Published: May 11, 2026
Source: NVD
CVE-2026-33357 HIGH - 7.5

In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearicloud.com can be abused to retrieve WAN IP data for arbitrary devices. The root cause is ...

Vendor: Meari
Product: com.meari.sdk
Published: May 11, 2026
Source: NVD
CVE-2026-33356 HIGH - 7.7

In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. The broker enforces publish restrictions but does not enforce equivalent subscribe authorization at p...

Vendor: Meari
Product: IoT Cloud MQTT Broker EMQX
Published: May 11, 2026
Source: NVD
CVE-2026-31254 HIGH - 7.3

The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python eval() function as a Hydra configuration resolver under the name eval. This allows configuration file...

Published: May 11, 2026
Source: NVD
CVE-2026-31253 HIGH - 7.3

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in checkpoint.py and the checkpoint loading code in eval.py use to...

Published: May 11, 2026
Source: NVD
CVE-2026-31251 HIGH - 7.3

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads the speech synthesis model from a user-specified directory using torch.load() without enabling the w...

Published: May 11, 2026
Source: NVD