Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,481 - 7,500 of 35,345 CVEs
CVE-2026-41207 MEDIUM - 5.3

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distinguish success from failure. Since this output is used as HKDF key material for the response AEAD, a ...

Vendor: maven
Product: io.netty.incubator:netty-incubator-codec-ohttp
Published: May 26, 2026
Source: GitHub
CVE-2026-9603 MEDIUM - 6.5

A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been...

Published: May 26, 2026
Source: NVD
CVE-2026-9584 HIGH - 7.3

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and ...

Published: May 26, 2026
Source: NVD
CVE-2026-5260 HIGH - 8.2

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

Published: May 26, 2026
Source: NVD
CVE-2026-48710 MEDIUM - 6.5

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed hea...

Vendor: Kludex
Product: starlette
Published: May 26, 2026
Source: NVD
CVE-2026-44905 HIGH - 7.5

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically val...

Vendor: riebl
Product: vanetza
Published: May 26, 2026
Source: NVD

Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting ...

Vendor: prometheus
Product: prometheus
Published: May 26, 2026
Source: NVD
CVE-2026-43988 HIGH - 7.5

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing corrupted ASN.1/OER structures (e.g., invalid length fi...

Vendor: riebl
Product: vanetza
Published: May 26, 2026
Source: NVD
CVE-2026-42015 MEDIUM - 5.3

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of s...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 26, 2026
Source: NVD
CVE-2026-42013 HIGH - 8.2

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 26, 2026
Source: NVD
CVE-2026-42012 HIGH - 7.1

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 26, 2026
Source: NVD
CVE-2025-46307 MEDIUM - 5.5

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-46284 HIGH - 7.0

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-46280 MEDIUM - 5.5

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43451 MEDIUM - 5.5

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43306 HIGH - 7.8

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43290 MEDIUM - 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to modify protected parts of the file system.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43289 MEDIUM - 5.5

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2026-9642 CRITICAL - 9.8

There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView project.

Vendor: deltaww
Product: diaview
Published: May 26, 2026
Source: NVD
CVE-2026-9583 MEDIUM - 4.3

A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be per...

Published: May 26, 2026
Source: NVD