Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,461 - 7,480 of 35,345 CVEs
CVE-2026-44644 MEDIUM - 6.1

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a flaw in the strip_html filter logic. The strip_html filter is intended to remove HTML tags from a string before rendering, and is widely used as an XSS...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub
CVE-2026-44632 CRITICAL - 9.1

Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-44596 MEDIUM - 6.5

Yamcs has No Rate Limiting on Authentication Endpoint

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-44595 MEDIUM - 4.3

Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-44587 MEDIUM - 4.7

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in string entries, causing the denylist to silently not match the content types it is intended to block. In lib/carrierwave/up...

Vendor: rubygems
Product: carrierwave
Published: May 27, 2026
Source: GitHub

Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations

Vendor: go
Product: github.com/kata-containers/kata-containers
Published: May 26, 2026
Source: GitHub

Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

Kirby CMS's `pages.access` permission is not checked during rendering of page drafts

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass

Vendor: npm
Product: fuxa-server
Published: May 26, 2026
Source: GitHub

FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue

Vendor: npm
Product: fuxa-server
Published: May 26, 2026
Source: GitHub

FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

Vendor: npm
Product: @frangoteam/fuxa
Published: May 26, 2026
Source: GitHub
CVE-2026-42568 MEDIUM - 4.3

Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13....

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 26, 2026
Source: GitHub
CVE-2026-42462 HIGH - 7.0

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linke...

Vendor: npm
Product: @fedify/fedify
Published: May 26, 2026
Source: GitHub
CVE-2026-9604 MEDIUM - 4.3

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. U...

Published: May 26, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: May 26, 2026
Source: NVD
CVE-2026-8647 MEDIUM - 4.8

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::...

Published: May 26, 2026
Source: NVD
CVE-2026-46740 MEDIUM - 5.3

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd...

Vendor: RRWO
Product: Mojolicious::Plugin::Statsd
Published: May 26, 2026
Source: NVD
CVE-2026-42089 HIGH - 8.6

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass at...

Vendor: npm
Product: yeoman-environment
Published: May 26, 2026
Source: GitHub