Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,812
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,881 - 7,900 of 36,708 CVEs
CVE-2026-47675 MEDIUM - 4.3

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), but does not apply the same validation to sameSite a...

Vendor: honojs
Product: hono
Published: May 28, 2026
Source: NVD
CVE-2026-47674 MEDIUM - 5.3

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 rep...

Vendor: honojs
Product: hono
Published: May 28, 2026
Source: NVD
CVE-2026-47673 MEDIUM - 4.8

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value โ€” regardless of the scheme name in the first position โ€” proceeds to J...

Vendor: honojs
Product: hono
Published: May 28, 2026
Source: NVD

GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application. An attacker can inject a malicious link in a pull request body, which if clicked by the user allows for a...

Vendor: gitbutlerapp
Product: gitbutler
Published: May 28, 2026
Source: NVD
CVE-2026-44466 HIGH - 8.6

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like echo. This vulnerability is fixed in 0.229.0.

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-44465 HIGH - 8.6

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration option. This allows an attacker to achieve Remote Code Execution (RCE) when a victim open a folder in untrusted mode. T...

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-44463 HIGH - 8.6

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-44462 MEDIUM - 6.4

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This vulnerability is fixed in 0.229.0.

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD
CVE-2026-44461 HIGH - 8.6

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or validation. If an attacker can control an environment variable key (for example via project terminal...

Vendor: zed-industries
Product: zed
Published: May 28, 2026
Source: NVD

When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unmarshaled configuration map (stdinData) at INFO level to /var/...

Vendor: Tigera
Product: Calico, Calico Enterprise, Calico Cloud
Published: May 28, 2026
Source: NVD

In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes the live Kubernetes ServiceAccount bearer token before logging...

Vendor: Tigera
Product: Calico
Published: May 28, 2026
Source: NVD
CVE-2026-41160 MEDIUM - 4.3

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit permissions for the parent object. Due to a "write first, au...

Vendor: espocrm
Product: espocrm
Published: May 28, 2026
Source: NVD
CVE-2026-41141 MEDIUM - 6.5

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter and resolves the owning entity (Contact, Lead, Account, or User) without performing an ACL check. An authenticated user with E...

Vendor: espocrm
Product: espocrm
Published: May 28, 2026
Source: NVD
CVE-2026-38707 CRITICAL - 9.8

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-38704 CRITICAL - 9.8

A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devic...

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-38703 CRITICAL - 9.8

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target device...

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-38702 CRITICAL - 9.8

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target device...

Vendor: inhandnetworks
Product: ir315_firmware
Published: May 28, 2026
Source: NVD
CVE-2026-24444 CRITICAL - 9.8

SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the rec...

Vendor: SDMC Technology Co., Ltd
Product: NE6037
Published: May 28, 2026
Source: NVD
CVE-2026-41178 MEDIUM - 5.3

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.

Vendor: go
Product: go.opentelemetry.io/otel/baggage
Published: May 28, 2026
Source: GitHub
CVE-2026-22872 MEDIUM - 9.1

Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for cluster-scoped resources. Prior to version 0.13.0, tenant admini...

Vendor: go
Product: github.com/projectcapsule/capsule
Published: May 28, 2026
Source: GitHub