Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 581 - 600 of 3,184 CVEs
CVE-2026-39830 CRITICAL - 9.1

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

Vendor: golang.org/x/crypto
Product: golang.org/x/crypto/ssh
Published: May 22, 2026
Source: NVD
CVE-2026-9264 CRITICAL - 9.3

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers t...

Published: May 22, 2026
Source: NVD
CVE-2026-34910 CRITICAL - 10.0

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Published: May 22, 2026
Source: NVD
CVE-2026-34909 CRITICAL - 10.0

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

Published: May 22, 2026
Source: NVD
CVE-2026-34908 CRITICAL - 10.0

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Published: May 22, 2026
Source: NVD
CVE-2026-33000 CRITICAL - 9.1

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Vendor: Ubiquiti Inc
Product: UniFi OS Server
Published: May 22, 2026
Source: NVD
CVE-2026-6960 CRITICAL - 9.8

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to uploa...

Published: May 21, 2026
Source: NVD
CVE-2026-46703 CRITICAL - 9.6

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in ...

Vendor: pip
Product: boxlite
Published: May 21, 2026
Source: GitHub
CVE-2026-46695 CRITICAL - 10.0

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the director...

Vendor: pip
Product: boxlite
Published: May 21, 2026
Source: GitHub

Twig: PHP code injection via `{% use %}` template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub
CVE-2026-46614 CRITICAL - 9.8

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route β€” /fission-function/<name> and /fission-function/<ns>/<name> β€”...

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-48207 CRITICAL - 9.8

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Pyt...

Vendor: Apache Software Foundation
Product: Apache Fory
Published: May 21, 2026
Source: NVD
CVE-2026-39531 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0.

Vendor: Wp Directory Kit
Product: WP Directory Kit
Published: May 21, 2026
Source: NVD
CVE-2025-71211 CRITICAL - 9.8

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable. Please note: although this vulnerabil...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2025-71210 CRITICAL - 9.8

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-5118 CRITICAL - 9.8

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured ...

Published: May 21, 2026
Source: NVD
CVE-2026-5433 CRITICAL - 9.1

Honeywell Control Network Module (CNM)Β contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).

Vendor: honeywell
Product: control_network_module_firmware
Published: May 21, 2026
Source: NVD
CVE-2026-44050 CRITICAL - 9.9

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-6279 CRITICAL - 9.8

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-...

Published: May 21, 2026
Source: NVD
CVE-2026-48172 CRITICAL - 9.8

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. LiteSpeed WHM Plugin (the parent plugin) is unaffected. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs...

Vendor: LiteSpeed Technologies
Product: cPanel Plugin
Published: May 21, 2026
Source: NVD