Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,753
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,261 - 6,280 of 35,119 CVEs
CVE-2026-42998 MEDIUM - 6.0

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credent...

Vendor: OpenStack
Product: Keystone
Published: May 28, 2026
Source: NVD
CVE-2026-30761 HIGH - 7.3

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

Published: May 28, 2026
Source: NVD
CVE-2026-30760 HIGH - 7.3

An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

Published: May 28, 2026
Source: NVD
CVE-2026-46439 HIGH - 7.8

compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-46405 MEDIUM - 5.3

OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46380 MEDIUM - 6.7

compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub
CVE-2026-45323 CRITICAL - 9.6

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewi...

Vendor: jpettitt
Product: meshcore-card
Published: May 28, 2026
Source: NVD
CVE-2026-45307 MEDIUM - 6.1

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urljoin(request.host_url, target) before parsing, while the controller passed the raw target to redirect(...

Vendor: murtaza-nasir
Product: speakr
Published: May 28, 2026
Source: NVD

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS api/auth/auth_project.py:14-38 and EE ee/api/auth/auth_project.py:14-46) only runs projects.is_autho...

Vendor: openreplay
Product: openreplay
Published: May 28, 2026
Source: NVD
CVE-2026-45296 HIGH - 7.7

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API key itself is valid and that the target projectKey exists. The authorization flow does not veri...

Vendor: openreplay
Product: openreplay
Published: May 28, 2026
Source: NVD
CVE-2026-34126 HIGH - 7.5

TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range...

Vendor: TP-Link Systems Inc., TP Link Systems Inc.
Product: Tapo L535E v1.0, v3.0, Tapo P300 v1.0, Tapo D100C v1.0
Published: May 28, 2026
Source: NVD

OpenBao's Inline Auth Incorrectly Redacted Headers

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub
CVE-2026-46345 HIGH - 8.4

compliance-trestle - jinja has an Arbitrary File Write via Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

Vendor: go
Product: github.com/openbao/openbao
Published: May 28, 2026
Source: GitHub

compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 28, 2026
Source: GitHub

Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits โ€” ReDoS

Vendor: composer
Product: symfony/json-path
Published: May 28, 2026
Source: GitHub

Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC โ€” Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/mailtrap-mailer
Published: May 28, 2026
Source: GitHub

Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret โ€” Unauthenticated Webhook Event Injection

Vendor: composer
Product: symfony/lox24-notifier
Published: May 28, 2026
Source: GitHub

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on each successful `ParseFile` call. `ParseFile` opens the schema file and passes it to `Parse` without clo...

Vendor: go
Product: go.opentelemetry.io/otel/schema/v1.1
Published: May 28, 2026
Source: GitHub
CVE-2026-9098 CRITICAL - 9.1

In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identit...

Published: May 28, 2026
Source: NVD