Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,018
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 7,661 - 7,680 of 35,345 CVEs
CVE-2026-46368 HIGH - 8.8

luci-app-https-dns-proxy through 2025.12.29-5 β€” an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default β€” contains a command injection vulnerability in the setInitAction function. An authenticated user holdi...

Vendor: mossdef-org
Product: luci-app-https-dns-proxy
Published: May 26, 2026
Source: NVD
CVE-2026-45247 CRITICAL - 9.8

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted cal...

Vendor: Mirasvit
Product: Full Page Cache Warmer for Magento 2
Published: May 26, 2026
Source: NVD
CVE-2026-45082 HIGH - 7.6

Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward ...

Vendor: karakeep-app
Product: karakeep
Published: May 26, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a duplicate of CVE-2026-43918. Notes: All CVE users should reference CVE-2026-43918 instead of this candidate.

Published: May 26, 2026
Source: NVD
CVE-2026-42785 HIGH - 7.2

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands i...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD
CVE-2026-42425 HIGH - 7.2

OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/Da...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason: This candidate is a duplicate of CVE-2026-28496. Notes: All CVE users should reference CVE-2026-28496 instead of this candidate.

Published: May 26, 2026
Source: NVD
CVE-2026-41917 MEDIUM - 4.9

OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with action=Load. Attackers can ...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD
CVE-2026-41401 MEDIUM - 6.5

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadat...

Vendor: libyang
Product: libyang
Published: May 26, 2026
Source: NVD
CVE-2026-40034 HIGH - 7.8

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attack...

Vendor: gitoxide
Product: gitoxide
Published: May 26, 2026
Source: NVD
CVE-2026-40033 HIGH - 8.8

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry d...

Vendor: FreeRDP
Product: FreeRDP
Published: May 26, 2026
Source: NVD
CVE-2026-9544 HIGH - 7.3

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to...

Published: May 26, 2026
Source: NVD
CVE-2026-9543 CRITICAL - 9.8

A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The...

Published: May 26, 2026
Source: NVD
CVE-2026-9542 MEDIUM - 6.3

A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available...

Published: May 26, 2026
Source: NVD
CVE-2026-9541 MEDIUM - 5.3

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been re...

Vendor: squirrel-lang
Product: squirrel
Published: May 26, 2026
Source: NVD
CVE-2026-9540 MEDIUM - 5.3

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The...

Published: May 26, 2026
Source: NVD

IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is conf...

Published: May 26, 2026
Source: NVD
CVE-2026-8174 MEDIUM - 5.7

Zohocorp Zoho Mail wordpress plugin is vulnerable toΒ Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.

Published: May 26, 2026
Source: NVD
CVE-2026-7374 CRITICAL - 9.9

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink ...

Published: May 26, 2026
Source: NVD

A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful expl...

Published: May 26, 2026
Source: NVD