Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,944
Quick preset (or use dates below)
Clear Filters
Showing 581 - 600 of 3,522 CVEs
CVE-2026-42680 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

Vendor: Wasiliy Strecker / ContestGallery developer
Product: Contest Gallery Pro
Published: Jun 01, 2026
Source: NVD
CVE-2026-47413 CRITICAL - 9.6

praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members

Vendor: pip
Product: praisonai-platform
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47428 CRITICAL - 9.6

Vitest browser mode serves unsanitized otelCarrier query parameter as inline script

Vendor: npm
Product: @vitest/browser
Published: Jun 01, 2026
Source: GitHub
CVE-2026-47429 CRITICAL - 9.8

When Vitest UI server is listening, arbitrary file can be read and executed

Vendor: npm
Product: vitest
Published: Jun 01, 2026
Source: GitHub
CVE-2026-7858 CRITICAL - 9.8

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.

Published: Jun 01, 2026
Source: NVD
CVE-2026-42252 CRITICAL - 9.1

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag auth...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Jun 01, 2026
Source: NVD
CVE-2026-48188 CRITICAL - 9.1

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mo...

Vendor: OTRS AG
Product: OTRS, ((OTRS)) Community Edition
Published: Jun 01, 2026
Source: NVD
CVE-2026-10187 CRITICAL - 9.8

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is pos...

Vendor: Totolink
Product: N300RH
Published: May 31, 2026
Source: NVD
CVE-2018-25412 CRITICAL - 9.8

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them...

Vendor: Deltasql
Product: Delta Sql
Published: May 30, 2026
Source: NVD
CVE-2026-47416 CRITICAL - 9.6

praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47410 CRITICAL - 9.8

praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub

PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47391 CRITICAL - 9.8

PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47392 CRITICAL - 9.9

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

Vendor: pip
Product: praisonaiagents
Published: May 29, 2026
Source: GitHub
CVE-2026-47393 CRITICAL - 9.8

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47396 CRITICAL - 9.8

PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-45700 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against ...

Vendor: FreeRDP
Product: FreeRDP
Published: May 29, 2026
Source: NVD
CVE-2026-45372 CRITICAL - 9.9

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so ...

Vendor: yhirose
Product: cpp-httplib
Published: May 29, 2026
Source: NVD
CVE-2026-9051 CRITICAL - 9.1

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  Successful exploitation requires an attacker to send a...

Published: May 29, 2026
Source: NVD
CVE-2026-47744 CRITICAL - 9.9

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public act...

Vendor: shopperlabs
Product: shopper
Published: May 29, 2026
Source: NVD