Total CVEs

133,733

Critical Severity

2,966

High Severity

10,851

Last 7 Days

1,628
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 6,141 - 6,160 of 30,138 CVEs
CVE-2026-41509 CRITICAL - 9.8

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.

Vendor: CROSS-signature
Product: CROSS-implementation
Published: May 08, 2026
Source: NVD
CVE-2026-41507 CRITICAL - 9.8

math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without sanitization. This allows an attacker to execute arbitrary system commands when user-controlled input reaches the par...

Vendor: mauriciopoppe
Product: math-codegen
Published: May 08, 2026
Source: NVD
CVE-2026-41506 MEDIUM - 4.7

go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.

Vendor: go-git
Product: go-git
Published: May 08, 2026
Source: NVD
CVE-2026-41497 CRITICAL - 9.8

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables like bash, python, or /bin/sh with inline code execution flags to pass thr...

Vendor: MervinPraison
Product: PraisonAI
Published: May 08, 2026
Source: NVD
CVE-2026-41496 HIGH - 8.1

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends β€” MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, Surr...

Vendor: MervinPraison
Product: PraisonAI
Published: May 08, 2026
Source: NVD
CVE-2026-41493 HIGH - 7.5

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. Thi...

Vendor: lsegal
Product: yard
Published: May 08, 2026
Source: NVD
CVE-2026-41491 HIGH - 8.1

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-rc.1 to before 1.16.14, and 1.17.0-rc.1 to before 1.17.5, a vulnerability has been found in Dapr that allows bypassing access control policies for serv...

Vendor: dapr
Product: dapr
Published: May 08, 2026
Source: NVD
CVE-2026-41423 MEDIUM - 5.3

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server due to improper han...

Vendor: angular
Product: angular
Published: May 08, 2026
Source: NVD
CVE-2026-41161 MEDIUM - 5.3

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response ti...

Vendor: Sync-in
Product: server
Published: May 08, 2026
Source: NVD
CVE-2026-39816 HIGH - 8.8

The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Scrip...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: May 08, 2026
Source: NVD

Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information ta...

Vendor: Dell
Product: PowerScale OneFS
Published: May 08, 2026
Source: NVD
CVE-2025-71302 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules Commit 506aa8b02a8d6 ("dma-fence: Add safe access helpers and document the rules") details the dma-fence safe access rules. The most common culprit is that drm_sched_fence...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-71301 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap/vunmap Acquire and release the GEM object's reservation lock around vmap and vunmap operations. The tests use vmap_locked, which led to errors such as show below. [ 122.29...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-71300 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" This reverts commit 06d22ed6b6635b17551f386b50bb5aaff9b75fbe. OP-TEE logic in U-Boot automatically injects a reserved-memory node along with optee firmware n...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-71299 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing The recent refactoring of where runtime PM is enabled done in commit f1eb4e792bb1 ("spi: spi-cadence-quadspi: Enable pm runtime earlier to avoid imbal...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-71298 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madvise Acquire and release the GEM object's reservation lock around calls to the object's madvide operation. The tests use drm_gem_shmem_madvise_locked(), which led to erro...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-71297 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode() rtw8822b_set_antenna() can be called from userspace when the chip is powered off. In that case a WARNING is triggered in rtw8822b_config_trx_mode() because trying to ...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD
CVE-2025-71296 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purge Acquire and release the GEM object's reservation lock around calls to the object's purge operation. The tests use drm_gem_shmem_purge_locked(), which led to errors suc...

Vendor: Linux
Product: Linux
Published: May 08, 2026
Source: NVD

Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls, leaving security entirely to the frontend. By modifying the binary string in the β€˜Permissions’ field of the JSON response, an attacker could escalate ...

Published: May 08, 2026
Source: NVD
CVE-2026-25199 CRITICAL - 9.1

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxmox extension for CloudStack improperly uses a user-editable instance setting, proxmox_vmid, to associ...

Vendor: Apache Software Foundation
Product: Apache CloudStack
Published: May 08, 2026
Source: NVD