Total CVEs

133,799

Critical Severity

2,967

High Severity

10,862

Last 7 Days

1,625
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,281 - 6,300 of 30,204 CVEs
CVE-2022-45899 MEDIUM - 6.5

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

Published: May 08, 2026
Source: NVD
CVE-2022-26523 MEDIUM - 5.3

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.

Published: May 08, 2026
Source: NVD
CVE-2022-26522 HIGH - 7.8

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.

Published: May 08, 2026
Source: NVD
CVE-2022-23961 MEDIUM - 6.1

In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.

Published: May 08, 2026
Source: NVD
CVE-2026-8136 LOW - 2.4

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may...

Published: May 08, 2026
Source: NVD
CVE-2026-8133 HIGH - 7.3

A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Filelist API. Such manipulation of the argument order leads to sql injection. The attack can be launched re...

Published: May 08, 2026
Source: NVD
CVE-2026-8132 HIGH - 7.3

A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be u...

Published: May 08, 2026
Source: NVD
CVE-2026-8131 HIGH - 7.3

A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the argument msgid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public ...

Published: May 08, 2026
Source: NVD
CVE-2026-8130 HIGH - 7.3

A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be us...

Published: May 08, 2026
Source: NVD
CVE-2026-8129 HIGH - 7.3

A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of the argument delwlistid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclo...

Published: May 08, 2026
Source: NVD
CVE-2026-44298 MEDIUM - 4.1

Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can upload PDF invoice templates, which can call pdfContext.setOption('associated_files', ...) ins...

Vendor: kimai
Product: kimai
Published: May 08, 2026
Source: NVD
CVE-2026-43944 CRITICAL - 9.6

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or openin...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-43943 HIGH - 7.8

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code execution (RCE) vulnerability exists in electerm's SFTP open with system editor or "Edit with custom editor" feature. When a user opts to edit a file using open wit...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-43942 MEDIUM - 5.5

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is accessi...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-43941 CRITICAL - 9.6

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal ...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-43940 HIGH - 8.4

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating userโ€‘supplied widget identifiers without any sanitisation. Because runWidget is...

Vendor: electerm
Product: electerm
Published: May 08, 2026
Source: NVD
CVE-2026-42275 HIGH - 8.7

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a l...

Vendor: openziti
Product: zrok
Published: May 08, 2026
Source: NVD

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3. This discrepancy can...

Vendor: dadrus
Product: heimdall
Published: May 08, 2026
Source: NVD

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are case-insensitive. This discrepancy can result in heimdall failing to match a rule for a request host tha...

Vendor: dadrus
Product: heimdall
Published: May 08, 2026
Source: NVD

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (%2f) is not recognize...

Vendor: dadrus
Product: heimdall
Published: May 08, 2026
Source: NVD