Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,635
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 5,741 - 5,760 of 34,996 CVEs
CVE-2026-44829 HIGH - 8.8

Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: May 29, 2026
Source: GitHub

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 29, 2026
Source: NVD
CVE-2026-48501 HIGH - 7.4

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authenticatio...

Vendor: cli
Product: cli
Published: May 29, 2026
Source: NVD
CVE-2026-45663 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly in...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45662 HIGH - 8.8

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shE...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-44962 CRITICAL - 9.9

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the serve...

Vendor: WebPros
Product: Plesk
Published: May 29, 2026
Source: NVD
CVE-2026-39276 HIGH - 7.2

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or dir...

Published: May 29, 2026
Source: NVD
CVE-2026-39229 MEDIUM - 6.5

Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information

Published: May 29, 2026
Source: NVD
CVE-2026-36324 MEDIUM - 6.1

SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php.

Published: May 29, 2026
Source: NVD
CVE-2026-35674 HIGH - 8.8

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and operator.admin scope r...

Vendor: OpenClaw
Product: OpenClaw
Published: May 29, 2026
Source: NVD
CVE-2026-35673 MEDIUM - 6.5

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by reusing blocked tabs to export or inspect content that should re...

Vendor: OpenClaw
Product: OpenClaw
Published: May 29, 2026
Source: NVD
CVE-2026-35630 HIGH - 8.0

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authorization.

Vendor: OpenClaw
Product: OpenClaw
Published: May 29, 2026
Source: NVD
CVE-2026-34507 MEDIUM - 5.4

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execute restricted behavior that policy should have bloc...

Vendor: OpenClaw
Product: OpenClaw
Published: May 29, 2026
Source: NVD

QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the opensolution.org server and serving arbitrary HTML or JavaScript at the plugin list endpoint. When a...

Vendor: OpenSolution
Product: QuickCMS
Published: May 29, 2026
Source: NVD

QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to vers...

Vendor: OpenSolution
Product: QuickCMS
Published: May 29, 2026
Source: NVD
CVE-2026-32906 MEDIUM - 4.3

OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypass intended approval splits to approve plugin actio...

Vendor: OpenClaw
Product: OpenClaw
Published: May 29, 2026
Source: NVD
CVE-2026-32905 HIGH - 8.3

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices...

Vendor: OpenClaw
Product: OpenClaw
Published: May 29, 2026
Source: NVD
CVE-2026-10101 MEDIUM - 6.3

ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, but can read `InfraEnv` objects and recover the referenced Secret&#...

Vendor: Red Hat
Product: Multicluster Engine for Kubernetes
Published: May 29, 2026
Source: NVD
CVE-2026-10099 MEDIUM - 4.0

XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted application data by sending unmasked WebSocket frames. The server unconditionally reads 4 bytes as a masking key regardless of whe...

Vendor: XX-net
Product: XX-Net
Published: May 29, 2026
Source: NVD
CVE-2026-10069 HIGH - 7.5

A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource consumption. The attack may be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products ...

Vendor: Shibby
Product: Tomato
Published: May 29, 2026
Source: NVD