Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,230
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,061 - 7,080 of 35,861 CVEs
CVE-2026-48522 MEDIUM - 4.2

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no ...

Vendor: jpadilla
Product: pyjwt
Published: May 28, 2026
Source: NVD

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

Vendor: py-pdf
Product: pypdf
Published: May 28, 2026
Source: NVD
CVE-2026-48155 MEDIUM - 5.5

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets. This vulnerability is fixed in 6.12.0.

Vendor: py-pdf
Product: pypdf
Published: May 28, 2026
Source: NVD
CVE-2026-47762 HIGH - 8.7

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This v...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-47761 HIGH - 8.7

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugi...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-47760 HIGH - 8.7

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerabili...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-47759 HIGH - 8.7

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypa...

Vendor: tinymce
Product: tinymce
Published: May 28, 2026
Source: NVD
CVE-2026-44358 HIGH - 8.2

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for bot...

Vendor: espressif
Product: shared-github-dangerjs
Published: May 28, 2026
Source: NVD
CVE-2026-41565 HIGH - 7.5

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied the caller-supplied authentication tag into a fixed 144-byte stack buffer...

Vendor: MIK
Product: CryptX
Published: May 28, 2026
Source: NVD
CVE-2026-35676 HIGH - 8.2

phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending P...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD
CVE-2026-35675 HIGH - 8.2

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via emai...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD
CVE-2026-35672 HIGH - 7.5

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers can send an empty x-pmf-token header to bypass token validation and inject malicious content via POST ...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD
CVE-2026-35671 HIGH - 8.8

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to Su...

Vendor: thorsten
Product: phpMyFAQ
Published: May 28, 2026
Source: NVD

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServe...

Published: May 28, 2026
Source: NVD

A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue was fixed in version 4.4.3

Published: May 28, 2026
Source: NVD

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests.

Published: May 28, 2026
Source: NVD

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint.

Published: May 28, 2026
Source: NVD
CVE-2026-49238 HIGH - 8.4

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The functi...

Vendor: Canonical
Product: Multipass
Published: May 28, 2026
Source: NVD
CVE-2026-49237 HIGH - 7.8

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-s...

Vendor: Canonical
Product: Multipass
Published: May 28, 2026
Source: NVD

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89f...

Vendor: bzip2
Product: bzip2
Published: May 28, 2026
Source: NVD