Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 601 - 620 of 3,184 CVEs
CVE-2026-47372 CRITICAL - 9.1

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

Vendor: RRWO
Product: Crypt::SaltedHash
Published: May 20, 2026
Source: NVD
CVE-2026-8631 CRITICAL - 9.8

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.

Vendor: hp
Product: linux_imaging_and_printing
Published: May 20, 2026
Source: NVD
CVE-2026-9141 CRITICAL - 9.8

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages without any session management or server-side authentication checks. Attackers w...

Published: May 20, 2026
Source: NVD
CVE-2026-9139 CRITICAL - 9.8

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static plaintext credentials in the page source. Unauthentic...

Published: May 20, 2026
Source: NVD
CVE-2026-45444 CRITICAL - 10.0

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

Vendor: WP Swings
Product: Gift Cards For WooCommerce Pro
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without ...

Vendor: xwiki
Product: xwiki-platform
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnera...

Vendor: xwiki
Product: xwiki-commons
Published: May 20, 2026
Source: NVD
CVE-2026-20223 CRITICAL - 10.0

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication wh...

Vendor: Cisco
Product: Cisco Secure Workload
Published: May 20, 2026
Source: NVD
CVE-2026-8598 CRITICAL - 9.1

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.

Published: May 20, 2026
Source: NVD

Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)

Vendor: npm
Product: @cap-js/sqlite
Published: May 20, 2026
Source: GitHub

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler in 'Elixir.PhoenixStorybook.Story.PlaygroundPreviewLive':handle_ev...

Vendor: erlang
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD
CVE-2026-22314 CRITICAL - 9.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems.Β This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Ser...

Vendor: Mesalvo
Product: Meona Client Launcher Component, Meona Server Component
Published: May 20, 2026
Source: NVD
CVE-2026-42960 CRITICAL - 10.0

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such recor...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-33278 CRITICAL - 9.8

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vuln...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-7637 CRITICAL - 9.8

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in...

Published: May 20, 2026
Source: NVD
CVE-2026-24207 CRITICAL - 9.8

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-7284 CRITICAL - 9.8

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can reg...

Published: May 20, 2026
Source: NVD
CVE-2026-6555 CRITICAL - 9.8

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and upl...

Published: May 20, 2026
Source: NVD
CVE-2026-8495 CRITICAL - 9.8

Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.

Published: May 19, 2026
Source: NVD
CVE-2026-34234 CRITICAL - 10.0

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler f...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD