Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,354
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,501 - 7,520 of 35,345 CVEs
CVE-2026-9582 MEDIUM - 4.3

A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to ...

Published: May 26, 2026
Source: NVD
CVE-2026-9581 MEDIUM - 6.3

A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 3.9.2...

Published: May 26, 2026
Source: NVD
CVE-2026-9580 HIGH - 7.3

A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may ...

Published: May 26, 2026
Source: NVD
CVE-2026-9579 MEDIUM - 6.3

A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. The attack may be launched remotely. The exploit has...

Published: May 26, 2026
Source: NVD
CVE-2026-8676 HIGH - 8.8

An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.

Published: May 26, 2026
Source: NVD

Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory exhaustion via unbounded cron range expansion. An attacker with access to schedule cron jobs can submit a malicious cron expression such as "0 0 1-100000000 * *"...

Vendor: oban-bg
Product: oban_web
Published: May 26, 2026
Source: NVD

Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution. The handle_event("save-job", ...) handler in 'Elixir.Oban.Web.Jobs.DetailComponent' does not perform an authorization c...

Vendor: oban-bg
Product: oban_web
Published: May 26, 2026
Source: NVD
CVE-2026-47672 MEDIUM - 6.5

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g....

Vendor: oviva-ag
Product: epa4all-client
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow tables or GPU-accelerated brute force (hashcat). This vulnerability is fixed in 2.9.1.

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetched server-side without any URL validation or internal IP filtering. This vulnerability is fixed in 2...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD
CVE-2026-44847 HIGH - 7.5

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns (None, {}), which Django REST Framework interprets as successful authe...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD
CVE-2026-44451 CRITICAL - 9.3

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSou...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44450 CRITICAL - 9.9

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution ...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44449 CRITICAL - 9.1

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename is concatenated directly into the smbclient -c script without validation. smbcli...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44444 CRITICAL - 9.1

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json with a preinstall, posti...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44443 MEDIUM - 4.8

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's auth.api.signUpEmail() ca...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The endpoint uses application_id from the URL path without validating ownership, allowing attackers to perf...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access in...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch (chat/api/oss/get_url) endpoint. The vulnerability exists due to inconsistent URL parsing between the urlparse v...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD
CVE-2026-36239 MEDIUM - 4.3

PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

Published: May 26, 2026
Source: NVD