Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
Showing 4,781 - 4,800 of 13,825 CVEs
CVE-2026-41164 MEDIUM - 4.4

nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claim...

Vendor: go
Product: github.com/nuts-foundation/nuts-node
Published: May 05, 2026
Source: GitHub
CVE-2026-40934 MEDIUM - 6.8

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password r...

Vendor: pip
Product: jupyter-server
Published: May 05, 2026
Source: GitHub
CVE-2026-7844 MEDIUM - 6.3

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Compatible File Serv...

Published: May 05, 2026
Source: NVD
CVE-2026-6907 MEDIUM - 4.3

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported Django series (s...

Vendor: djangoproject
Product: django
Published: May 05, 2026
Source: NVD
CVE-2026-5766 MEDIUM - 5.3

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation. As a reminder, Django expects a ...

Vendor: djangoproject
Product: django
Published: May 05, 2026
Source: NVD
CVE-2026-39103 MEDIUM - 5.5

Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svg_attributes.c, svg_parse_strings(), gf_svg_parse_attribute()

Published: May 05, 2026
Source: NVD
CVE-2026-35192 MEDIUM - 6.5

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Dja...

Vendor: djangoproject
Product: Django
Published: May 05, 2026
Source: NVD
CVE-2026-34956 MEDIUM - 5.9

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a ...

Published: May 05, 2026
Source: NVD
CVE-2026-34002 MEDIUM - 6.1

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory bound...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: May 05, 2026
Source: NVD
CVE-2026-34000 MEDIUM - 6.1

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an attacker to read uninitialized or out-of-bounds memory. An attacker with a connection to the X11 server...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: May 05, 2026
Source: NVD
CVE-2025-61669 MEDIUM - 6.1

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.co...

Vendor: jupyter-server
Product: jupyter_server
Published: May 05, 2026
Source: NVD
CVE-2025-52206 MEDIUM - 4.7

ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

Vendor: ispconfig
Product: ispconfig
Published: May 05, 2026
Source: NVD
CVE-2026-7778 MEDIUM - 5.0

An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N (5.0, Medium). This iss...

Published: May 05, 2026
Source: NVD
CVE-2026-28510 MEDIUM - 5.9

eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an...

Vendor: elabftw
Product: elabftw
Published: May 05, 2026
Source: NVD
CVE-2026-27694 MEDIUM - 5.4

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping. An attacker with low privileges can store crafte...

Vendor: traccar
Product: traccar
Published: May 05, 2026
Source: NVD
CVE-2026-27693 MEDIUM - 5.4

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML co...

Vendor: traccar
Product: traccar
Published: May 05, 2026
Source: NVD
CVE-2026-27644 MEDIUM - 6.5

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported field...

Vendor: traccar
Product: traccar
Published: May 05, 2026
Source: NVD
CVE-2026-6262 MEDIUM - 6.5

The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload path (`mfn-icon-upload`) in a filesystem move operation without constraining it to the uploads directory...

Published: May 05, 2026
Source: NVD
CVE-2026-43574 MEDIUM - 6.5

OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43572 MEDIUM - 5.3

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invoke requests that are processed without proper validation, all...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD