Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

867
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 541 - 560 of 27,228 CVEs
CVE-2026-27173 HIGH - 8.7

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Ai...

Vendor: Apache Software Foundation
Product: Apache Airflow CNCF Kubernetes provider
Published: May 19, 2026
Source: NVD

FileBrowser Quantum: unauthenticated user share share info

Vendor: go
Product: github.com/gtsteffaniak/filebrowser/backend
Published: May 19, 2026
Source: GitHub
CVE-2026-46374 HIGH - 7.5

SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser

Vendor: pip
Product: sqlfluff
Published: May 19, 2026
Source: GitHub
CVE-2026-46373 HIGH - 7.5

SQLFluff: Recursive Stack Overflow in Parser

Vendor: pip
Product: sqlfluff
Published: May 19, 2026
Source: GitHub
CVE-2026-46372 HIGH - 8.5

SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

Vendor: npm
Product: sillytavern
Published: May 19, 2026
Source: GitHub
CVE-2026-46378 HIGH - 7.5

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

Vendor: go
Product: github.com/tomwright/dasel/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-46377 HIGH - 7.5

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

Vendor: go
Product: github.com/tomwright/dasel/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-45783 HIGH - 7.5

@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes

Vendor: npm
Product: @libp2p/kad-dht
Published: May 19, 2026
Source: GitHub
CVE-2026-46354 CRITICAL - 9.1

Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft

Vendor: go
Product: github.com/coder/coder/v2
Published: May 19, 2026
Source: GitHub

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

Vendor: npm
Product: nuxt
Published: May 19, 2026
Source: GitHub
CVE-2026-46338 MEDIUM - 4.3

Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path

Vendor: pip
Product: pymdown-extensions
Published: May 19, 2026
Source: GitHub
CVE-2026-45805 HIGH - 8.8

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint โ€” RCE

Vendor: npm
Product: @penpot/mcp
Published: May 19, 2026
Source: GitHub

FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service

Vendor: composer
Product: setasign/fpdi
Published: May 19, 2026
Source: GitHub
CVE-2026-45799 HIGH - 7.5

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

Vendor: maven
Product: com.squareup.wire:wire-runtime-jvm
Published: May 19, 2026
Source: GitHub
CVE-2026-45796 MEDIUM - 6.5

Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint

Vendor: go
Product: github.com/coder/coder/v2
Published: May 19, 2026
Source: GitHub
CVE-2026-46357 MEDIUM - 6.5

HAX CMS: Denial of Service using Malicious Import Request

Vendor: npm
Product: @haxtheweb/haxcms-nodejs
Published: May 19, 2026
Source: GitHub
CVE-2026-45785 MEDIUM - 6.2

OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle

Vendor: nuget
Product: OpenMcdf
Published: May 19, 2026
Source: GitHub

rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers

Vendor: rust
Product: openssl
Published: May 19, 2026
Source: GitHub
CVE-2026-46339 CRITICAL - 10.0

9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

Vendor: npm
Product: 9router
Published: May 19, 2026
Source: GitHub
CVE-2026-45695 CRITICAL - 9.8

Kopia: RCE via SSH ProxyCommand Injection

Vendor: go
Product: github.com/kopia/kopia
Published: May 19, 2026
Source: GitHub