Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,641 - 6,660 of 35,847 CVEs
CVE-2026-44494 HIGH - 8.7

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-th...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub
CVE-2026-44492 HIGH - 8.6

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe)...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub
CVE-2026-44490 MEDIUM - 4.8

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the p...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.use...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub

Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escapin...

Vendor: composer
Product: froxlor/froxlor
Published: May 29, 2026
Source: GitHub
CVE-2026-41236 HIGH - 8.8

Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` under a customer-controlled home directory without ...

Vendor: composer
Product: froxlor/froxlor
Published: May 29, 2026
Source: GitHub
CVE-2026-41235 HIGH - 8.8

Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when processing add or edit requ...

Vendor: composer
Product: froxlor/froxlor
Published: May 29, 2026
Source: GitHub
CVE-2026-4290 CRITICAL - 9.1

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete(...

Published: May 29, 2026
Source: NVD
CVE-2026-39292 HIGH - 7.3

Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and...

Published: May 29, 2026
Source: NVD
CVE-2026-10063 HIGH - 8.8

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and mi...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 29, 2026
Source: NVD
CVE-2026-10062 HIGH - 8.8

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. The attack is possible to be carried out remotely. The ex...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 29, 2026
Source: NVD
CVE-2026-10042 CRITICAL - 9.8

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name} endpoints deserialize attacker-controlled HTTP request...

Vendor: zyddnys
Product: manga-image-translator
Published: May 29, 2026
Source: NVD
CVE-2026-49325 MEDIUM - 4.6

Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via ...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a pr...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a pr...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-49316 MEDIUM - 4.6

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN e...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-47696 MEDIUM - 4.3

WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST parameter. The endpoint contains a TODO for real Authorize.Net charging, hardcodes $paymentSuccess...

Vendor: WWBN
Product: AVideo
Published: May 29, 2026
Source: NVD
CVE-2026-47694 MEDIUM - 5.4

WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScript in a category description, which executes when ...

Vendor: WWBN
Product: AVideo
Published: May 29, 2026
Source: NVD
CVE-2026-46376 CRITICAL - 9.8

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP ...

Vendor: FreePBX
Product: security-reporting
Published: May 29, 2026
Source: NVD
CVE-2026-45615 HIGH - 8.2

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, th...

Vendor: mouse07410
Product: asn1c
Published: May 29, 2026
Source: NVD