Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 4,701 - 4,720 of 12,537 CVEs
CVE-2026-3456 HIGH - 7.5

The GeekyBot β€” Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributekey' parameter in versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient pre...

Published: May 05, 2026
Source: NVD
CVE-2026-35228 HIGH - 8.7

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server ...

Vendor: Oracle Corporation
Product: Oracle MCP Server Helper Tool product of Oracle Open Source Projects
Published: May 05, 2026
Source: NVD
CVE-2026-5100 HIGH - 7.5

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published: May 05, 2026
Source: NVD
CVE-2026-44028 HIGH - 7.5

An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite m...

Vendor: NixOS, Lix Project
Product: Nix, Lix
Published: May 05, 2026
Source: NVD
CVE-2026-42264 HIGH - 7.4

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making the...

Vendor: npm
Product: axios
Published: May 05, 2026
Source: GitHub
CVE-2026-7788 HIGH - 7.3

A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_document/continue_document/delete_document/get_content of the file app/routes/document.py. Performing a manipulation of the argument DOCS_DIR/...

Published: May 05, 2026
Source: NVD
CVE-2026-7785 HIGH - 7.3

A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotel...

Published: May 05, 2026
Source: NVD
CVE-2026-7784 HIGH - 7.3

A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.py of the component Skills Endpoint. Such manipulation of the argument Name leads to path traversal. It is possible to launch the attack remotely. The ...

Published: May 05, 2026
Source: NVD
CVE-2026-7791 HIGH - 7.8

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading ...

Published: May 04, 2026
Source: NVD
CVE-2026-7776 HIGH - 7.5

Boundary Community Edition and Boundary Enterprise (β€œBoundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate duri...

Published: May 04, 2026
Source: NVD
CVE-2026-42313 HIGH - 8.3

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The allowlist ...

Vendor: pip
Product: pyload-ng
Published: May 04, 2026
Source: GitHub

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions ...

Vendor: rubygems
Product: net-imap
Published: May 04, 2026
Source: GitHub
CVE-2026-42575 HIGH - 7.5

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifies the signature on APKINDEX.tar.gz but never compares individually downloaded .apk packages against the checksum recorded in the signed index. The checksum is parsed and available...

Vendor: go
Product: chainguard.dev/apko
Published: May 04, 2026
Source: GitHub
CVE-2026-42574 HIGH - 7.5

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or l...

Vendor: go
Product: chainguard.dev/apko
Published: May 04, 2026
Source: GitHub
CVE-2026-42606 HIGH - 8.1

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password reset URL sent to an...

Vendor: composer
Product: azuracast/azuracast
Published: May 04, 2026
Source: GitHub
CVE-2026-42605 HIGH - 8.8

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem s...

Vendor: composer
Product: azuracast/azuracast
Published: May 04, 2026
Source: GitHub
CVE-2026-42222 HIGH - 8.1

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.

Vendor: 0xJacky
Product: nginx-ui
Published: May 04, 2026
Source: NVD
CVE-2026-42221 HIGH - 8.1

Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without...

Vendor: 0xJacky
Product: nginx-ui
Published: May 04, 2026
Source: NVD
CVE-2026-41895 HIGH - 7.5

changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external entity resolution, external DTD loading, or network-backed enti...

Vendor: pip
Product: changedetection.io
Published: May 04, 2026
Source: GitHub
CVE-2026-41893 HIGH - 7.5

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSo...

Vendor: npm
Product: signalk-server
Published: May 04, 2026
Source: GitHub