Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,604
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,441 - 7,460 of 36,815 CVEs
CVE-2026-47390 MEDIUM - 5.5

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

Vendor: pip
Product: praisonaiagents
Published: May 29, 2026
Source: GitHub
CVE-2026-47398 HIGH - 8.1

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-9831 MEDIUM - 6.3

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue w...

Published: May 29, 2026
Source: NVD
CVE-2026-47268 MEDIUM - 6.4

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.10, an authenticated Nezha dashboard user can create or update a DDNS profile with provider webhook and configure an arbitrary webhook_url, HTTP method, reque...

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 29, 2026
Source: GitHub
CVE-2026-47233 MEDIUM - 6.5

Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` โ€” incomplete fix of #2024

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47234 MEDIUM - 4.4

Admidio writes session IDs and auto-login cookie values to application logs

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47232 MEDIUM - 4.3

Admidio PKCS#12 private key export action lacks CSRF protection

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47231 HIGH - 8.1

Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47230 MEDIUM - 6.5

Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47229 MEDIUM - 5.4

Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47228 MEDIUM - 5.2

Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47227 MEDIUM - 6.5

Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules/categories.php`

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47226 MEDIUM - 6.5

Admidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47213 MEDIUM - 6.5

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is tri...

Vendor: pip
Product: boxlite
Published: May 29, 2026
Source: GitHub

Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification

Vendor: composer
Product: symfony/symfony
Published: May 29, 2026
Source: GitHub

ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .env

Vendor: pip
Product: ouroboros-ai
Published: May 29, 2026
Source: GitHub

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, when a user authenticates via Basic Auth (i.e via the `Authorization` header with the `Basic` scheme)...

Vendor: go
Product: github.com/authelia/authelia/v4
Published: May 29, 2026
Source: GitHub
CVE-2026-47201 HIGH - 8.5

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed ass...

Vendor: go
Product: goauthentik.io
Published: May 29, 2026
Source: GitHub

CC-Tweaked has an SSRF Protection Bypass with NAT64

Vendor: maven
Product: cc.tweaked:cc-tweaked-1.21-core
Published: May 29, 2026
Source: GitHub
CVE-2026-47184 MEDIUM - 6.5

zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood

Vendor: pip
Product: zeroconf
Published: May 29, 2026
Source: GitHub