Total CVEs

140,279

Critical Severity

3,710

High Severity

13,344

Last 7 Days

1,816
Quick preset (or use dates below)
Clear Filters
Showing 4,801 - 4,820 of 13,344 CVEs
CVE-2023-42346 HIGH - 7.5

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

Published: May 08, 2026
Source: NVD
CVE-2023-42344 HIGH - 7.3

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

Published: May 08, 2026
Source: NVD
CVE-2022-26522 HIGH - 7.8

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.

Published: May 08, 2026
Source: NVD
CVE-2026-8133 HIGH - 7.3

A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Filelist API. Such manipulation of the argument order leads to sql injection. The attack can be launched re...

Published: May 08, 2026
Source: NVD
CVE-2026-8132 HIGH - 7.3

A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be u...

Published: May 08, 2026
Source: NVD
CVE-2026-8131 HIGH - 7.3

A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the argument msgid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public ...

Published: May 08, 2026
Source: NVD
CVE-2026-8130 HIGH - 7.3

A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be us...

Published: May 08, 2026
Source: NVD
CVE-2026-8129 HIGH - 7.3

A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of the argument delwlistid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclo...

Published: May 08, 2026
Source: NVD
CVE-2026-43943 HIGH - 7.8

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code execution (RCE) vulnerability exists in electerm's SFTP open with system editor or "Edit with custom editor" feature. When a user opts to edit a file using open wit...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-43940 HIGH - 8.4

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating user‑supplied widget identifiers without any sanitisation. Because runWidget is...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-42275 HIGH - 8.7

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a l...

Vendor: openziti
Product: zrok
Published: May 08, 2026
Source: NVD
CVE-2026-42271 HIGH - 8.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration ...

Vendor: BerriAI
Product: litellm
Published: May 08, 2026
Source: NVD
CVE-2026-42261 HIGH - 7.1

PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills.ts exposes an authenticated endpoint POST /api/skills/fetch-remote that fetches a user-supplied URL server-side and reflects the response body (up to ...

Vendor: legeling
Product: PromptHub
Published: May 08, 2026
Source: NVD
CVE-2026-42203 HIGH - 8.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the Lit...

Vendor: BerriAI
Product: litellm
Published: May 08, 2026
Source: NVD
CVE-2026-8128 HIGH - 7.3

A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of the argument msgid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made publ...

Published: May 08, 2026
Source: NVD
CVE-2026-8126 HIGH - 7.3

A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Published: May 08, 2026
Source: NVD
CVE-2026-6411 HIGH - 7.3

This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Due to the presence of a hardcoded AES key within the application, the encrypted data can be decrypted, ena...

Published: May 07, 2026
Source: NVD
CVE-2026-7541 HIGH - 7.5

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies w...

Vendor: github
Product: enterprise_server
Published: May 07, 2026
Source: NVD
CVE-2026-41105 HIGH - 8.1

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_monitor_action_group_notification_system
Published: May 07, 2026
Source: NVD
CVE-2026-40213 HIGH - 7.4

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments c...

Vendor: OpenStack
Product: Cyborg
Published: May 07, 2026
Source: NVD