Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,441 - 7,460 of 35,345 CVEs
CVE-2026-9609 MEDIUM - 4.7

A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem ear...

Published: May 27, 2026
Source: NVD
CVE-2026-9608 LOW - 2.4

A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been public...

Published: May 27, 2026
Source: NVD
CVE-2026-9207 HIGH - 8.8

Tanium addressed an unauthorized code execution vulnerability in Connect.

Vendor: tanium
Product: connect
Published: May 27, 2026
Source: NVD
CVE-2026-9156 MEDIUM - 6.5

Tanium addressed a denial of service vulnerability in Tanium Server.

Vendor: tanium
Product: server
Published: May 27, 2026
Source: NVD
CVE-2026-7493 MEDIUM - 5.3

The Appointment Booking Calendar โ€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function...

Published: May 27, 2026
Source: NVD
CVE-2026-6565 MEDIUM - 6.4

The Style Kits โ€“ Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient in...

Published: May 27, 2026
Source: NVD

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unrespo...

Vendor: OpenStack
Product: Swift
Published: May 27, 2026
Source: NVD
CVE-2026-49014 HIGH - 7.4

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribu...

Vendor: GDAL
Product: GDAL
Published: May 27, 2026
Source: NVD

@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects

Vendor: npm
Product: @hapi/wreck
Published: May 27, 2026
Source: GitHub

@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters

Vendor: npm
Product: @hapi/content
Published: May 27, 2026
Source: GitHub
CVE-2026-44741 HIGH - 8.8

Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter

Vendor: composer
Product: pimcore/admin-ui-classic-bundle
Published: May 27, 2026
Source: GitHub
CVE-2026-44739 HIGH - 8.7

Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub
CVE-2026-44705 HIGH - 8.2

tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../...

Vendor: npm
Product: tmp
Published: May 27, 2026
Source: GitHub
CVE-2026-44646 MEDIUM - 5.3

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, Context.spawn() creates a child Context for the {% render %} tag but does not propagate the parent context's resolved ownPropertyOnly value, resulting in a silent bypass. The...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub
CVE-2026-9607 MEDIUM - 6.3

A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public an...

Published: May 27, 2026
Source: NVD
CVE-2026-9606 HIGH - 7.3

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be us...

Published: May 27, 2026
Source: NVD
CVE-2026-9605 HIGH - 7.3

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be u...

Published: May 27, 2026
Source: NVD
CVE-2026-9312 HIGH - 8.2

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request par...

Vendor: github
Product: enterprise_server
Published: May 27, 2026
Source: NVD
CVE-2026-8606 MEDIUM - 5.9

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measu...

Vendor: github
Product: enterprise_server
Published: May 27, 2026
Source: NVD
CVE-2026-44645 MEDIUM - 6.5

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can be fully bypassed by a {% for %} (or {% tablerow %}) tag whose body is empty. The renderLimit option is documented in docs/source/tutorials/dos.md as th...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub