Total CVEs

139,258

Critical Severity

3,630

High Severity

13,017

Last 7 Days

1,250
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,861 - 7,880 of 35,663 CVEs
CVE-2026-3603 HIGH - 7.1

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit t...

Vendor: ibm
Product: engineering_lifecycle_management
Published: May 26, 2026
Source: NVD
CVE-2026-9567 LOW - 3.3

A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public...

Published: May 26, 2026
Source: NVD
CVE-2026-9566 MEDIUM - 4.3

A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the component Sign-up. The manipulation of the argument redirect leads to cross site scripting. The attack is possible to be carried ou...

Published: May 26, 2026
Source: NVD
CVE-2026-9560 HIGH - 7.8

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

Vendor: openvpn
Product: connect
Published: May 26, 2026
Source: NVD
CVE-2026-9170 HIGH - 7.5

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to denial of service and a potential remote code execution due to improper input validation.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8856 HIGH - 7.7

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8855 HIGH - 8.1

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8854 HIGH - 7.5

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8835 HIGH - 7.3

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8834 HIGH - 8.0

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8633 CRITICAL - 9.8

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.

Vendor: ibm
Product: websphere_application_server
Published: May 26, 2026
Source: NVD
CVE-2026-8620 HIGH - 7.5

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.

Vendor: ibm
Product: websphere_application_server
Published: May 26, 2026
Source: NVD
CVE-2026-7454 HIGH - 7.8

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7453 MEDIUM - 5.3

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7452 HIGH - 7.8

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7451 HIGH - 7.8

A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7450 MEDIUM - 5.3

A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7251 CRITICAL - 9.8

Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have ful...

Published: May 26, 2026
Source: NVD
CVE-2026-48696 MEDIUM - 6.2

FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48695 HIGH - 8.1

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() c...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD