Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

851
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 701 - 720 of 27,228 CVEs

The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.

Vendor: TYPO3
Product: Extension "Faceted Search"
Published: May 19, 2026
Source: NVD

The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.

Vendor: TYPO3
Product: Extension "Faceted Search"
Published: May 19, 2026
Source: NVD

The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.

Vendor: TYPO3
Product: Extension "Faceted Search"
Published: May 19, 2026
Source: NVD

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to conte...

Vendor: TYPO3
Product: Extension "Frontend User Registration"
Published: May 19, 2026
Source: NVD
CVE-2026-46586 HIGH - 7.3

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.0...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-45434 HIGH - 8.8

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-45187 MEDIUM - 6.5

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-41919 CRITICAL - 9.1

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-35086 MEDIUM - 6.5

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31986 CRITICAL - 9.1

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31910 HIGH - 7.5

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31909 HIGH - 7.5

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31906 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31388 MEDIUM - 5.3

Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31387 MEDIUM - 5.3

Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31380 MEDIUM - 6.5

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31379 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue aff...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-31378 MEDIUM - 6.5

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD
CVE-2026-2611 CRITICAL - 9.6

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine...

Published: May 19, 2026
Source: NVD
CVE-2026-29226 HIGH - 7.3

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: May 19, 2026
Source: NVD