Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,988
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 5,601 - 5,620 of 34,871 CVEs
CVE-2026-10108 HIGH - 7.5

xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated attackers to read arbitrary files outside the intended music directory by exploiting an incomplete path prefix check. Attackers can request files from sib...

Vendor: hanxi
Product: xiaomusic
Published: May 29, 2026
Source: NVD
CVE-2026-10107 HIGH - 7.7

MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token cookie and a URL whose domain matches the assembled allowlist. Attackers can bypass internal network protections ...

Vendor: jxxghp
Product: MoviePilot
Published: May 29, 2026
Source: NVD
CVE-2026-10105 HIGH - 8.3

agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickho...

Vendor: agno-agi
Product: agno
Published: May 29, 2026
Source: NVD
CVE-2026-10070 MEDIUM - 4.7

A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor deleted the GitH...

Vendor: macrozheng
Product: mall
Published: May 29, 2026
Source: NVD
CVE-2026-47139 HIGH - 8.6

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes und...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47140 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, and inspector. However, the denylist misses process and inspector/promises. Both can be used from sandboxed code to reach host-si...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47210 CRITICAL - 9.8

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending). ...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47137 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is t...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47209 HIGH - 8.6

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inher...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47135 HIGH - 8.7

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbo...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47208 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47131 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError con...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47200 MEDIUM - 5.3

Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, when experimental.componentIslands is enabled (default in Nuxt 4), any .s...

Vendor: npm
Product: nuxt
Published: May 29, 2026
Source: GitHub
CVE-2026-45742 HIGH - 7.5

Gotenberg has a Race Condition via Multipart `downloadFrom` Handling

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 29, 2026
Source: GitHub
CVE-2026-45741 HIGH - 7.5

Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 29, 2026
Source: GitHub
CVE-2026-44829 HIGH - 8.8

Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 29, 2026
Source: GitHub

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 29, 2026
Source: NVD
CVE-2026-48501 HIGH - 7.4

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authenticatio...

Vendor: cli
Product: cli
Published: May 29, 2026
Source: NVD
CVE-2026-45663 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly in...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45662 HIGH - 8.8

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shE...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD