Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 7,341 - 7,360 of 35,861 CVEs
CVE-2026-44888 CRITICAL - 9.8

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly into pialert.conf without validation. Since pialert.conf is loaded via Python's exec() eve...

Vendor: leiweibau
Product: Pi.Alert
Published: May 27, 2026
Source: NVD
CVE-2026-44887 CRITICAL - 9.8

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. Since the background scan daemon loads this file via Python's exec(), injected code executes...

Vendor: leiweibau
Product: Pi.Alert
Published: May 27, 2026
Source: NVD

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devices.php route accepts requests from unauthenticated users when the action URL parameter is set to get...

Vendor: leiweibau
Product: Pi.Alert
Published: May 27, 2026
Source: NVD
CVE-2026-44590 CRITICAL - 9.3

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltr...

Vendor: sherlock-project
Product: sherlock
Published: May 27, 2026
Source: NVD
CVE-2026-42197 HIGH - 8.7

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's browser session, potentially leading to full admin ...

Vendor: inducer
Product: relate
Published: May 27, 2026
Source: NVD

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

Published: May 27, 2026
Source: NVD

Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification

Vendor: composer
Product: symfony/html-sanitizer
Published: May 27, 2026
Source: GitHub

Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters β†’ Visual href Spoofing

Vendor: composer
Product: symfony/html-sanitizer
Published: May 27, 2026
Source: GitHub
CVE-2026-44982 HIGH - 7.2

CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests

Vendor: go
Product: github.com/crowdsecurity/crowdsec
Published: May 27, 2026
Source: GitHub

CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression

Vendor: go
Product: github.com/crowdsecurity/crowdsec
Published: May 27, 2026
Source: GitHub
CVE-2026-44726 HIGH - 7.4

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attemp...

Vendor: rust
Product: deno
Published: May 27, 2026
Source: GitHub
CVE-2026-25879 CRITICAL - 9.8

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e....

Vendor: pip
Product: langroid
Published: May 27, 2026
Source: GitHub
CVE-2026-8716 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

Vendor: gitlab
Product: gitlab
Published: May 27, 2026
Source: NVD
CVE-2026-6713 MEDIUM - 5.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.

Vendor: gitlab
Product: gitlab
Published: May 27, 2026
Source: NVD
CVE-2026-5296 MEDIUM - 4.3

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated user with developer-role permissions to bypass flow restrictions...

Vendor: gitlab
Product: gitlab
Published: May 27, 2026
Source: NVD
CVE-2026-4868 HIGH - 8.2

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to impro...

Vendor: gitlab
Product: gitlab
Published: May 27, 2026
Source: NVD
CVE-2026-2601 MEDIUM - 4.3

GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to impr...

Vendor: gitlab
Product: gitlab
Published: May 27, 2026
Source: NVD
CVE-2026-1402 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.

Vendor: gitlab
Product: gitlab
Published: May 27, 2026
Source: NVD
CVE-2026-45618 CRITICAL - 10.0

LiquidJS is Vulnerable to Remote Code Execution

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub
CVE-2026-5509 HIGH - 7.2

An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s...

Vendor: tp-link
Product: archer_be450_firmware
Published: May 27, 2026
Source: NVD