Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

959
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,761 - 7,780 of 35,348 CVEs
CVE-2026-9500 MEDIUM - 5.3

A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The explo...

Published: May 25, 2026
Source: NVD

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD
CVE-2026-48589 MEDIUM - 5.4

Apache Shiroโ€™s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. Thi...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: May 25, 2026
Source: NVD
CVE-2026-44598 MEDIUM - 5.4

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1,ย only when using shiro-jakarta-ee integration module. Users a...

Vendor: Apache Software Foundation
Product: Apache Shiro Jakarta EE module
Published: May 25, 2026
Source: NVD
CVE-2026-43828 MEDIUM - 6.5

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the ...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: May 25, 2026
Source: NVD
CVE-2026-43827 MEDIUM - 6.5

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: May 25, 2026
Source: NVD
CVE-2026-24597 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This issue affects Organization chart: from n/a through 1.7.5.

Vendor: WpDevArt
Product: Organization chart
Published: May 25, 2026
Source: NVD
CVE-2026-24574 MEDIUM - 6.5

Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.

Vendor: Recorp
Product: Export WP Page to Static HTML/CSS
Published: May 25, 2026
Source: NVD
CVE-2026-24545 MEDIUM - 4.3

Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.

Vendor: Nikki Blight
Product: QR Redirector
Published: May 25, 2026
Source: NVD
CVE-2026-9498 MEDIUM - 6.3

A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used in a template engine. ...

Published: May 25, 2026
Source: NVD
CVE-2026-9497 MEDIUM - 6.3

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this dis...

Published: May 25, 2026
Source: NVD
CVE-2026-9486 MEDIUM - 4.3

A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Published: May 25, 2026
Source: NVD
CVE-2026-9485 LOW - 3.5

A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is ...

Published: May 25, 2026
Source: NVD
CVE-2026-9484 MEDIUM - 6.3

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. T...

Published: May 25, 2026
Source: NVD
CVE-2026-48849 MEDIUM - 4.4

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48848 HIGH - 7.2

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48846 MEDIUM - 6.5

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD