Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,621 - 7,640 of 35,345 CVEs

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check after joining. A directory of ../../../tmp resolves cleanly to /tmp, outside the web root. This ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not goroutine-safe, concurrent requests race on the shared ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD
CVE-2026-40384 HIGH - 7.5

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-40383 CRITICAL - 9.8

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35223 CRITICAL - 9.8

An improper access check allows unauthorized access to com_config webservice endpoints.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35222 CRITICAL - 9.8

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35221 CRITICAL - 9.8

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35220 MEDIUM - 4.3

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30895 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30894 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the content history component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD

A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API pr...

Published: May 26, 2026
Source: NVD
CVE-2026-25901 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-25900 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the feed modules.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-24212 HIGH - 7.5

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Isaac Launchable
Published: May 26, 2026
Source: NVD
CVE-2026-24162 HIGH - 7.8

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: Merlin Transformers4Rec
Published: May 26, 2026
Source: NVD
CVE-2025-36221 MEDIUM - 5.3

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

Vendor: IBM
Product: Cloud Pak for Data System - Cyclops
Published: May 26, 2026
Source: NVD
CVE-2025-36220 MEDIUM - 4.3

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Vendor: IBM
Product: Cloud Pak for Data System - Cyclops
Published: May 26, 2026
Source: NVD
CVE-2025-36148 MEDIUM - 5.4

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the int...

Vendor: IBM
Product: Financial Transaction Manager for SWIFT Services for Multiplatforms
Published: May 26, 2026
Source: NVD
CVE-2025-36145 MEDIUM - 5.4

IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.

Vendor: IBM
Product: watsonx.data
Published: May 26, 2026
Source: NVD
CVE-2025-36126 MEDIUM - 6.4

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functi...

Vendor: IBM
Product: Cognos Analytics, Cognos Transformer
Published: May 26, 2026
Source: NVD