Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,701 - 5,720 of 34,871 CVEs
CVE-2026-49324 MEDIUM - 4.6

Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-vehicle network to permanently immobilize the motorcycle. The WCM enforces a brute-force lockout on the ...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-49323 MEDIUM - 4.3

Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-48527 HIGH - 8.7

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by in...

Vendor: haxtheweb
Product: haxcms-nodejs, haxcms-php
Published: May 29, 2026
Source: NVD

Rejected reason: Further research determined the issue is not a vulnerability.

Published: May 29, 2026
Source: NVD

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings for any user_id via index.php?r=core/saveSetting. A separate client-side sink in the email module in...

Vendor: Intermesh
Product: groupoffice
Published: May 29, 2026
Source: NVD
CVE-2026-45312 CRITICAL - 9.9

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas wor...

Vendor: infiniflow
Product: ragflow
Published: May 29, 2026
Source: NVD

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin). The endpoint ...

Vendor: rustfs
Product: rustfs
Published: May 29, 2026
Source: NVD
CVE-2026-10071 CRITICAL - 9.8

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Vendor: Interinfo
Product: DreamMaker
Published: May 29, 2026
Source: NVD
CVE-2026-9811 MEDIUM - 5.4

A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields....

Published: May 29, 2026
Source: NVD
CVE-2026-9809 HIGH - 7.6

A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user ...

Published: May 29, 2026
Source: NVD
CVE-2026-9808 HIGH - 7.1

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass own...

Published: May 29, 2026
Source: NVD
CVE-2026-9559 CRITICAL - 9.9

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (campaign...

Published: May 29, 2026
Source: NVD
CVE-2025-41281 HIGH - 7.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL conne...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41280 HIGH - 7.8

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41279 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41278 HIGH - 7.8

Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41277 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41276 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41275 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41274 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD