Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,725
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,581 - 6,600 of 35,133 CVEs
CVE-2026-44709 HIGH - 7.8

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set environment variables before pamusb-pinentry is invoked ca...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-21785 MEDIUM - 4.0

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

Vendor: HCLSoftware
Product: BigFix Remote Control Server
Published: May 27, 2026
Source: NVD

Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener

Vendor: composer
Product: symfony/monolog-bridge
Published: May 27, 2026
Source: GitHub

Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]

Vendor: composer
Product: symfony/http-kernel
Published: May 27, 2026
Source: GitHub

Symfony's Cas2Handler Derives CAS service URL from Client Host Header โ†’ Cross-Service Ticket Replay

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix

Vendor: composer
Product: symfony/cache
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() โ€” Unescaped Non-PHP File Rendering

Vendor: composer
Product: symfony/symfony
Published: May 27, 2026
Source: GitHub

Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true

Vendor: composer
Product: symfony/dom-crawler
Published: May 27, 2026
Source: GitHub

Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names

Vendor: composer
Product: symfony/mime
Published: May 27, 2026
Source: GitHub

Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address

Vendor: composer
Product: symfony/mailer
Published: May 27, 2026
Source: GitHub

Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address

Vendor: composer
Product: symfony/mime
Published: May 27, 2026
Source: GitHub
CVE-2026-9759 MEDIUM - 5.5

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

Vendor: wireshark
Product: wireshark
Published: May 27, 2026
Source: NVD
CVE-2026-8364 CRITICAL - 9.8

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.

Published: May 27, 2026
Source: NVD
CVE-2026-8363 CRITICAL - 9.8

A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:

Published: May 27, 2026
Source: NVD
CVE-2026-8362 CRITICAL - 9.8

A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome

Published: May 27, 2026
Source: NVD
CVE-2026-8361 HIGH - 7.5

A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome

Published: May 27, 2026
Source: NVD
CVE-2026-8360 HIGH - 7.5

Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being de...

Published: May 27, 2026
Source: NVD
CVE-2026-8359 HIGH - 7.5

When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that module. However, WOSHttpStatusModule.dll is n...

Published: May 27, 2026
Source: NVD

Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.

Published: May 27, 2026
Source: NVD