Total CVEs

133,898

Critical Severity

2,973

High Severity

10,891

Last 7 Days

1,515
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,861 - 6,880 of 30,303 CVEs
CVE-2026-41936 HIGH - 8.1

Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to ...

Vendor: givanz
Product: Vvveb
Published: May 06, 2026
Source: NVD
CVE-2026-41934 HIGH - 8.8

Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated users to execute arbitrary code by exploiting insufficient file extension restrictions. Attackers with editor, author, contributor, or site_admi...

Vendor: givanz
Product: Vvveb
Published: May 06, 2026
Source: NVD
CVE-2026-41931 MEDIUM - 5.3

Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. Attackers can access the admin password-reset endpoint to trigger a fatal error ...

Vendor: givanz
Product: Vvveb
Published: May 06, 2026
Source: NVD
CVE-2026-41930 CRITICAL - 9.8

Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain...

Vendor: givanz
Product: Vvveb
Published: May 06, 2026
Source: NVD
CVE-2026-34474 HIGH - 7.5

Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interface can expose sensitive device and account information. In affected builds, the response may include the administrator password and WLAN PSK, enabling authent...

Published: May 06, 2026
Source: NVD
CVE-2026-34473 HIGH - 7.5

Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST...

Published: May 06, 2026
Source: NVD
CVE-2026-0300 CRITICAL - 9.8

A buffer overflow vulnerability in the User-IDโ„ข Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. ...

Vendor: paloaltonetworks
Product: pan-os
Published: May 06, 2026
Source: NVD

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized changes.

Vendor: HCL Software
Product: BigFix Service Management (SM)
Published: May 06, 2026
Source: NVD
CVE-2025-31960 MEDIUM - 5.3

HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an ...

Vendor: HCL
Product: BigFix Service Management (SM)
Published: May 06, 2026
Source: NVD
CVE-2024-30151 HIGH - 8.3

HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorized users to gain elevated privileges, bypassing intended access restrictions. This may result in exposure of sensitive data or unauthorized system modi...

Vendor: HCL
Product: BigFix Service Management (SM)
Published: May 06, 2026
Source: NVD
CVE-2026-44305 MEDIUM - 6.8

Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a man-in-the-middle attacker positioned between Lemur and...

Vendor: pip
Product: lemur
Published: May 06, 2026
Source: GitHub
CVE-2026-33079 HIGH - 7.5

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles contains overlapping alte...

Vendor: lepture
Product: mistune
Published: May 06, 2026
Source: NVD
CVE-2026-29090 CRITICAL - 9.9

### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`. This allows any authenticated Rucio user to execute arbitrary SQL against the PostgreSQL metadata database through the DID search...

Vendor: rucio
Product: rucio
Published: May 06, 2026
Source: NVD

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.3.0, every IPv6 category bypasses is_url_safe. This vulnerability is fixed in 1.3.0.

Vendor: npm
Product: dssrf
Published: May 06, 2026
Source: GitHub

Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checkin...

Vendor: composer
Product: craftcms/cms
Published: May 06, 2026
Source: GitHub
CVE-2026-44226 MEDIUM - 5.3

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication and renders attacker-controlled template name...

Vendor: pip
Product: pyload-ng
Published: May 06, 2026
Source: GitHub

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled c...

Vendor: composer
Product: craftcms/cms
Published: May 06, 2026
Source: GitHub

Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read eve...

Vendor: composer
Product: craftcms/cms
Published: May 06, 2026
Source: GitHub

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular...

Vendor: go
Product: github.com/QuantumNous/new-api
Published: May 06, 2026
Source: GitHub
CVE-2026-7875 HIGH - 8.8

NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container to read files outside the intended outbox directory by supplying crafted messages_out.id and content....

Published: May 06, 2026
Source: NVD