Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,944
Quick preset (or use dates below)
Clear Filters
Showing 601 - 620 of 3,522 CVEs
CVE-2026-7786 CRITICAL - 9.8

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and used to authenticate to device services.

Published: May 29, 2026
Source: NVD
CVE-2026-5386 CRITICAL - 9.1

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.

Published: May 29, 2026
Source: NVD
CVE-2026-45661 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment. When combined with Dokploy's remote s...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45633 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authe...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45632 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to other organizations if they know the scheduleId/serverId....

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45631 CRITICAL - 10.0

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign-in as admin, and execute commands on the h...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45630 CRITICAL - 9.0

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote servers via unsanitized echo shell interpolation.

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45629 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compr...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-45628 CRITICAL - 9.6

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (which runs through /bin/sh -c). User-supplied branch names, repository URLs, and Docker credentials a...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-47140 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, and inspector. However, the denylist misses process and inspector/promises. Both can be used from sandboxed code to reach host-si...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47210 CRITICAL - 9.8

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending). ...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47137 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is t...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47208 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-47131 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError con...

Vendor: npm
Product: vm2
Published: May 29, 2026
Source: GitHub
CVE-2026-45663 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly in...

Vendor: Dokploy
Product: dokploy
Published: May 29, 2026
Source: NVD
CVE-2026-44962 CRITICAL - 9.9

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the serve...

Vendor: WebPros
Product: Plesk
Published: May 29, 2026
Source: NVD
CVE-2026-4290 CRITICAL - 9.1

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete(...

Published: May 29, 2026
Source: NVD
CVE-2026-10042 CRITICAL - 9.8

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name} endpoints deserialize attacker-controlled HTTP request...

Vendor: zyddnys
Product: manga-image-translator
Published: May 29, 2026
Source: NVD
CVE-2026-46376 CRITICAL - 9.8

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP ...

Vendor: FreePBX
Product: security-reporting
Published: May 29, 2026
Source: NVD
CVE-2026-45312 CRITICAL - 9.9

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas wor...

Vendor: infiniflow
Product: ragflow
Published: May 29, 2026
Source: NVD