Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,721 - 4,740 of 12,537 CVEs
CVE-2026-42311 HIGH - 7.8

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

Vendor: pip
Product: pillow
Published: May 04, 2026
Source: GitHub
CVE-2026-7768 HIGH - 7.5

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching Accept header variants to make the cache grow unbounded, eventually exhausting the Node.js...

Vendor: npm
Product: @fastify/accepts-serializer
Published: May 04, 2026
Source: NVD
CVE-2026-6321 HIGH - 7.5

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications...

Vendor: npm
Product: fast-uri
Published: May 04, 2026
Source: NVD
CVE-2025-67796 HIGH - 8.1

IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data...

Published: May 04, 2026
Source: NVD
CVE-2026-42301 HIGH - 7.8

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the summary field) into the generated spec file without escaping RPM macro directives. When a packager then runs rpmbuild, those directives get evaluated, so...

Vendor: pip
Product: pyp2spec
Published: May 04, 2026
Source: GitHub
CVE-2026-42295 HIGH - 4.9

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the workflow executor logs all artifact repository credentials (S3 access keys, secret keys, GCS service account keys, Azure account keys, Git ...

Vendor: go
Product: github.com/argoproj/argo-workflows/v4
Published: May 04, 2026
Source: GitHub
CVE-2026-42296 HIGH - 8.1

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod securit...

Vendor: go
Product: github.com/argoproj/argo-workflows/v3
Published: May 04, 2026
Source: GitHub
CVE-2026-42294 HIGH - 7.5

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the /api...

Vendor: go
Product: github.com/argoproj/argo-workflows/v3
Published: May 04, 2026
Source: GitHub
CVE-2026-42297 HIGH - 8.3

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provider (server/sync/sync_cm.go) performs zero authorization checks on all CRUD operations (create, r...

Vendor: go
Product: github.com/argoproj/argo-workflows/v4
Published: May 04, 2026
Source: GitHub

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versions 4.9.0 and 5.4.0.

Vendor: composer
Product: getkirby/cms
Published: May 04, 2026
Source: GitHub
CVE-2026-40893 HIGH - 8.2

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and change permissions for arbitrary files. Th...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 04, 2026
Source: GitHub
CVE-2026-42154 HIGH - 7.5

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a smal...

Vendor: prometheus
Product: prometheus
Published: May 04, 2026
Source: NVD
CVE-2026-42151 HIGH - 7.5

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving ...

Vendor: prometheus
Product: prometheus
Published: May 04, 2026
Source: NVD
CVE-2026-38751 HIGH - 7.2

OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)

Published: May 04, 2026
Source: NVD
CVE-2026-25863 HIGH - 7.5

Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters witho...

Vendor: Jules Colle
Product: Conditional Fields for Contact Form 7
Published: May 04, 2026
Source: NVD
CVE-2026-43616 HIGH - 7.1

Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extrac...

Vendor: horsicq
Product: DIE-engine
Published: May 04, 2026
Source: NVD
CVE-2026-42084 HIGH - 8.1

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid ses...

Vendor: OpenC3
Product: cosmos
Published: May 04, 2026
Source: NVD
CVE-2026-41471 HIGH - 7.5

Easy PayPal Events & Tickets plugin for WordPress versions 1.3 and earlier contain an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated attackers to enumerate and retrieve all customer order records. Attackers can iterate over sequential WordPress ...

Vendor: Scott Paterson
Product: easy-paypal-events-tickets
Published: May 04, 2026
Source: NVD
CVE-2026-37459 HIGH - 7.5

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Published: May 04, 2026
Source: NVD
CVE-2026-32834 HIGH - 7.5

Easy PayPal Events & Tickets plugin for WordPress version 1.3 and earlier contain a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated remote attackers to bypass hash verification by supplying 'test' as the hash parameter. At...

Vendor: Scott Paterson
Product: easy-paypal-events-tickets
Published: May 04, 2026
Source: NVD