Total CVEs

133,841

Critical Severity

2,972

High Severity

10,882

Last 7 Days

1,667
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,301 - 6,320 of 30,246 CVEs
CVE-2024-53326 HIGH - 7.3

LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.

Published: May 08, 2026
Source: NVD
CVE-2024-51092 CRITICAL - 9.1

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().

Vendor: librenms
Product: librenms
Published: May 08, 2026
Source: NVD
CVE-2024-46508 HIGH - 7.5

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

Vendor: yeti-platform
Product: yeti
Published: May 08, 2026
Source: NVD
CVE-2024-46507 HIGH - 7.3

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

Vendor: yeti-platform
Product: yeti
Published: May 08, 2026
Source: NVD
CVE-2024-45257 HIGH - 7.3

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

Published: May 08, 2026
Source: NVD
CVE-2024-33724 MEDIUM - 5.4

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

Published: May 08, 2026
Source: NVD
CVE-2024-33722 MEDIUM - 6.3

SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

Published: May 08, 2026
Source: NVD
CVE-2024-33288 HIGH - 7.3

Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

Published: May 08, 2026
Source: NVD
CVE-2024-30167 MEDIUM - 6.3

/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.

Published: May 08, 2026
Source: NVD
CVE-2024-27686 HIGH - 7.5

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Published: May 08, 2026
Source: NVD
CVE-2023-47268 MEDIUM - 5.3

In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.

Vendor: prusa3d
Product: prusaslicer
Published: May 08, 2026
Source: NVD
CVE-2026-8148 HIGH - 7.8

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

Vendor: navercorp
Product: mybox
Published: May 08, 2026
Source: NVD
CVE-2026-8138 HIGH - 8.8

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: tenda
Product: cx12l_firmware
Published: May 08, 2026
Source: NVD
CVE-2026-8137 HIGH - 8.8

A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclose...

Published: May 08, 2026
Source: NVD
CVE-2026-42279 MEDIUM - 5.8

solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization when the caller has time-entries:update:all in the URL organization, allowing a known foreign time-ent...

Vendor: solidtime-io
Product: solidtime
Published: May 08, 2026
Source: NVD

UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a critical logic flaw in its policy enforcement pipeline. When a transaction originates from a "Pocket" (a derived sub-address documented in the pr...

Vendor: UltraDAGcom
Product: core
Published: May 08, 2026
Source: NVD
CVE-2026-42277 MEDIUM - 6.5

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the caller is authenticated but never checks that the ...

Vendor: onyx-dot-app
Product: onyx
Published: May 08, 2026
Source: NVD
CVE-2026-42276 MEDIUM - 4.3

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session belongs to the call...

Vendor: onyx-dot-app
Product: onyx
Published: May 08, 2026
Source: NVD
CVE-2023-42346 HIGH - 7.5

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

Published: May 08, 2026
Source: NVD
CVE-2023-42345 MEDIUM - 6.1

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

Published: May 08, 2026
Source: NVD