Total CVEs

140,279

Critical Severity

3,710

High Severity

13,344

Last 7 Days

1,816
Quick preset (or use dates below)
Clear Filters
Showing 4,781 - 4,800 of 13,344 CVEs
CVE-2026-41496 HIGH - 8.1

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, Surr...

Vendor: MervinPraison
Product: PraisonAI
Published: May 08, 2026
Source: NVD
CVE-2026-41493 HIGH - 7.5

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. Thi...

Vendor: lsegal
Product: yard
Published: May 08, 2026
Source: NVD
CVE-2026-41491 HIGH - 8.1

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-rc.1 to before 1.16.14, and 1.17.0-rc.1 to before 1.17.5, a vulnerability has been found in Dapr that allows bypassing access control policies for serv...

Vendor: dapr
Product: dapr
Published: May 08, 2026
Source: NVD
CVE-2026-39816 HIGH - 8.8

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Scrip...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: May 08, 2026
Source: NVD
CVE-2025-66467 HIGH - 8.0

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access to it by using the previously generated...

Vendor: Apache Software Foundation
Product: Apache CloudStack
Published: May 08, 2026
Source: NVD
CVE-2022-50994 HIGH - 8.1

DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter. Attackers can exploit unsanitized...

Vendor: DrayTek
Product: Vigor 2960
Published: May 08, 2026
Source: NVD
CVE-2026-7330 HIGH - 7.2

The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escapin...

Published: May 08, 2026
Source: NVD
CVE-2026-5127 HIGH - 8.8

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files...

Published: May 08, 2026
Source: NVD
CVE-2026-43284 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-67888 HIGH - 7.3

An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated a...

Published: May 08, 2026
Source: NVD
CVE-2025-55449 HIGH - 7.3

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.

Vendor: astrbot
Product: astrbot
Published: May 08, 2026
Source: NVD
CVE-2024-53326 HIGH - 7.3

LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.

Published: May 08, 2026
Source: NVD
CVE-2024-46508 HIGH - 7.5

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

Vendor: yeti-platform
Product: yeti
Published: May 08, 2026
Source: NVD
CVE-2024-46507 HIGH - 7.3

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

Vendor: yeti-platform
Product: yeti
Published: May 08, 2026
Source: NVD
CVE-2024-45257 HIGH - 7.3

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

Published: May 08, 2026
Source: NVD
CVE-2024-33288 HIGH - 7.3

Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

Published: May 08, 2026
Source: NVD
CVE-2024-27686 HIGH - 7.5

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Published: May 08, 2026
Source: NVD
CVE-2026-8148 HIGH - 7.8

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

Vendor: navercorp
Product: mybox
Published: May 08, 2026
Source: NVD
CVE-2026-8138 HIGH - 8.8

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: tenda
Product: cx12l_firmware
Published: May 08, 2026
Source: NVD
CVE-2026-8137 HIGH - 8.8

A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclose...

Published: May 08, 2026
Source: NVD