Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

843
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 761 - 780 of 27,228 CVEs
CVE-2026-27737 MEDIUM - 6.5

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recordi...

Vendor: bigbluebutton, blindsidenetworks
Product: bigbluebutton, scalite, bbb-playback
Published: May 18, 2026
Source: NVD
CVE-2026-8851 HIGH - 8.1

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inj...

Published: May 18, 2026
Source: NVD
CVE-2026-8838 CRITICAL - 9.8

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.

Published: May 18, 2026
Source: NVD
CVE-2026-4137 HIGH - 7.0

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with ...

Published: May 18, 2026
Source: NVD
CVE-2026-27130 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input sanitization, lack of schema validation and direct shell interpolation. User-controlled application ...

Vendor: Dokploy
Product: dokploy
Published: May 18, 2026
Source: NVD

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected fi...

Vendor: FreePBX
Product: security-reporting
Published: May 18, 2026
Source: NVD
CVE-2026-46559 MEDIUM - 4.0

ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46557 MEDIUM - 6.2

ImageMagick: Stack overflow in fx operation

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46523 MEDIUM - 6.2

ImageMagick: Use-After-Free in MSL decoder.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46522 HIGH - 7.5

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46521 MEDIUM - 5.5

ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46520 HIGH - 7.5

ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45664 MEDIUM - 5.3

ImageMagick: Policy Bypass in MNG coder could

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45624 MEDIUM - 5.1

ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45367 HIGH - 7.5

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
Published: May 18, 2026
Source: GitHub
CVE-2026-45554 MEDIUM - 5.3

NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes

Vendor: pip
Product: nicegui
Published: May 18, 2026
Source: GitHub
CVE-2026-45553 HIGH - 7.5

NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

Vendor: pip
Product: nicegui
Published: May 18, 2026
Source: GitHub
CVE-2026-45686 HIGH - 7.5

OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45685 HIGH - 7.5

OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45684 MEDIUM - 4.9

OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub