Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,381 - 7,400 of 35,861 CVEs
CVE-2025-67903 MEDIUM - 5.3

Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.

Published: May 27, 2026
Source: NVD
CVE-2026-45617 HIGH - 7.5

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many <scri...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub

Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend

Vendor: composer
Product: getkirby/cms
Published: May 27, 2026
Source: GitHub
CVE-2026-45357 HIGH - 7.5

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime implementation parses width specifiers like %9999999d and forwards the captured width unchecked into pad()/padStart(), leading to memory and render...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub

Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions

Vendor: composer
Product: getkirby/cms
Published: May 27, 2026
Source: GitHub
CVE-2026-45260 HIGH - 8.1

Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub
CVE-2026-49054 MEDIUM - 4.3

Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.

Vendor: Mamunur Rashid
Product: The Post Grid
Published: May 27, 2026
Source: NVD
CVE-2026-48027 CRITICAL - 9.8

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and t...

Vendor: nrwl
Product: nx-console
Published: May 27, 2026
Source: NVD
CVE-2026-45335 MEDIUM - 5.4

WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=InternoControle. Th...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 27, 2026
Source: NVD
CVE-2026-45027 MEDIUM - 5.9

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/Func...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 27, 2026
Source: NVD
CVE-2026-42790 HIGH - 8.1

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. pe...

Vendor: Erlang
Product: OTP
Published: May 27, 2026
Source: NVD
CVE-2026-38945 HIGH - 7.8

Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.

Published: May 27, 2026
Source: NVD
CVE-2026-38931 MEDIUM - 5.4

A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.

Published: May 27, 2026
Source: NVD
CVE-2026-38930 MEDIUM - 6.5

OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the name cookie parameter.

Published: May 27, 2026
Source: NVD
CVE-2025-70116 MEDIUM - 4.3

A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV).

Published: May 27, 2026
Source: NVD
CVE-2025-68712 MEDIUM - 5.5

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authen...

Published: May 27, 2026
Source: NVD
CVE-2022-41656 MEDIUM - 4.3

Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from n/a through 2.1.2.

Vendor: Bizswoop
Product: Account Manager for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-45162 HIGH - 8.0

Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub

Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation โ†’ Off-Site //host URL Injection

Vendor: composer
Product: symfony/routing
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub