Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,761 - 6,780 of 35,345 CVEs

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

Vendor: Veeam
Product: Backup and Replication
Published: May 28, 2026
Source: NVD
CVE-2026-32995 HIGH - 7.5

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying roo...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: May 28, 2026
Source: NVD
CVE-2026-2374 HIGH - 7.2

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['P...

Published: May 28, 2026
Source: NVD

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send com...

Published: May 28, 2026
Source: NVD
CVE-2026-8915 HIGH - 8.8

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.

Vendor: samsung
Product: escargot
Published: May 28, 2026
Source: NVD
CVE-2026-4888 MEDIUM - 4.3

The Everest Forms โ€“ Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenti...

Published: May 28, 2026
Source: NVD

Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadv...

Published: May 27, 2026
Source: NVD
CVE-2026-46544 MEDIUM - 5.3

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages and reuses an existing in-memory session object if that session_id already exists. If a prior session ...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46538 MEDIUM - 5.9

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not verify that a TASK_END message came from the device that originally received the ...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46416 MEDIUM - 6.3

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for multiple authenticated WebSocket connections. The handler stores per-connection protocol objects in mutab...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46414 HIGH - 8.8

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46402 HIGH - 8.1

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause U...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-45322 HIGH - 7.8

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD

compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 27, 2026
Source: GitHub
CVE-2026-47717 HIGH - 7.5

FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations

Vendor: npm
Product: fuxa-server
Published: May 27, 2026
Source: GitHub

Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs

Vendor: go
Product: github.com/kata-containers/kata-containers
Published: May 27, 2026
Source: GitHub
CVE-2026-46621 CRITICAL - 9.1

Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-46562 CRITICAL - 9.8

Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub

Pimcore has a CustomReports Share Bypass

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub
CVE-2026-45703 MEDIUM - 6.4

Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub