Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,981 - 6,000 of 35,345 CVEs
CVE-2026-47228 MEDIUM - 5.2

Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47227 MEDIUM - 6.5

Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules/categories.php`

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47226 MEDIUM - 6.5

Admidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47213 MEDIUM - 6.5

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is tri...

Vendor: pip
Product: boxlite
Published: May 29, 2026
Source: GitHub

Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification

Vendor: composer
Product: symfony/symfony
Published: May 29, 2026
Source: GitHub

ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .env

Vendor: pip
Product: ouroboros-ai
Published: May 29, 2026
Source: GitHub

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, when a user authenticates via Basic Auth (i.e via the `Authorization` header with the `Basic` scheme)...

Vendor: go
Product: github.com/authelia/authelia/v4
Published: May 29, 2026
Source: GitHub
CVE-2026-47201 HIGH - 8.5

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed ass...

Vendor: go
Product: goauthentik.io
Published: May 29, 2026
Source: GitHub

CC-Tweaked has an SSRF Protection Bypass with NAT64

Vendor: maven
Product: cc.tweaked:cc-tweaked-1.21-core
Published: May 29, 2026
Source: GitHub
CVE-2026-47184 MEDIUM - 6.5

zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood

Vendor: pip
Product: zeroconf
Published: May 29, 2026
Source: GitHub

StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only b...

Published: May 29, 2026
Source: NVD
CVE-2026-48811 MEDIUM - 4.3

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's access to the mailbox containing the conversation has...

Vendor: freescout-help-desk
Product: freescout
Published: May 29, 2026
Source: NVD
CVE-2026-48810 MEDIUM - 4.3

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the same missing mailbox membership check was found in the sibling ThreadPolicy::edit method. A user with the PERM_EDIT_CO...

Vendor: freescout-help-desk
Product: freescout
Published: May 29, 2026
Source: NVD
CVE-2026-48557 HIGH - 8.8

Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() preserving inner .ph...

Vendor: spatie
Product: laravel-medialibrary
Published: May 29, 2026
Source: NVD
CVE-2026-48555 HIGH - 7.4

Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.

Vendor: spatie
Product: laravel-medialibrary
Published: May 29, 2026
Source: NVD

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21 and 3.1.26.

Vendor: verbb
Product: formie
Published: May 29, 2026
Source: NVD
CVE-2026-47123 HIGH - 7.5

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / References headers. The notification reply pa...

Vendor: freescout-help-desk
Product: freescout
Published: May 29, 2026
Source: NVD
CVE-2026-46599 HIGH - 7.5

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

Vendor: golang.org/x/image
Product: golang.org/x/image/tiff
Published: May 29, 2026
Source: NVD
CVE-2026-46527 HIGH - 7.5

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwarded-For header whose value parses to no valid...

Vendor: yhirose
Product: cpp-httplib
Published: May 29, 2026
Source: NVD
CVE-2026-45700 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against ...

Vendor: FreeRDP
Product: FreeRDP
Published: May 29, 2026
Source: NVD