Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

870
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 501 - 520 of 27,228 CVEs

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves be...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-43620 MEDIUM - 6.5

Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Attackers can exploit the vulnerability by setting CF_INC_RECURSE in compatibility flags and sending a sp...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-43619 MEDIUM - 6.3

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat that allow local attackers to redirect operations to files outside the exported rsync module. Attacke...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-43618 HIGH - 8.1

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buf...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-43617 MEDIUM - 4.8

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connec...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-3985 HIGH - 7.5

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficie...

Published: May 20, 2026
Source: NVD
CVE-2026-45585 MEDIUM - 6.8

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance ...

Vendor: microsoft
Product: windows_11_24h2
Published: May 20, 2026
Source: NVD
CVE-2026-39309 MEDIUM - 5.5

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission promp...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-35593 MEDIUM - 6.8

Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read sensitive arbitrary files from the server's filesystem....

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-8495 CRITICAL - 9.8

Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.

Published: May 19, 2026
Source: NVD
CVE-2026-8493 MEDIUM - 5.4

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS). This issue affects Colorbox Inline: from 0.0.0 before 2.1.1.

Published: May 19, 2026
Source: NVD
CVE-2026-8492 LOW - 2.7

Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.

Published: May 19, 2026
Source: NVD
CVE-2026-8491 LOW - 3.7

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.

Published: May 19, 2026
Source: NVD
CVE-2026-6871 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS). This issue affects Obfuscate: from 0.0.0 before 2.0.2.

Vendor: obfuscate_project
Product: obfuscate
Published: May 19, 2026
Source: NVD
CVE-2026-6367 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6366 MEDIUM - 6.6

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6365 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 1...

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6095 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS). This issue affects Orejime: from 0.0.0 before 2.0.16.

Vendor: gaya
Product: orejime
Published: May 19, 2026
Source: NVD
CVE-2026-34600 MEDIUM - 5.7

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully fixed by the prior pa...

Vendor: laurent22
Product: joplin
Published: May 19, 2026
Source: NVD
CVE-2026-5090 MEDIUM - 6.1

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' t...

Published: May 19, 2026
Source: NVD