Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,287
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,941 - 7,960 of 35,853 CVEs
CVE-2026-2255 MEDIUM - 4.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can...

Published: May 27, 2026
Source: NVD
CVE-2026-2254 MEDIUM - 6.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

Published: May 27, 2026
Source: NVD
CVE-2026-2253 HIGH - 7.7

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

Published: May 27, 2026
Source: NVD
CVE-2025-15649 MEDIUM - 5.5

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes ...

Vendor: PMQS
Product: IO::Uncompress::Unzip
Published: May 27, 2026
Source: NVD
CVE-2026-9632 HIGH - 8.8

A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible t...

Published: May 27, 2026
Source: NVD
CVE-2026-9631 HIGH - 8.8

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer ov...

Published: May 27, 2026
Source: NVD
CVE-2026-9628 HIGH - 8.8

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer ove...

Published: May 27, 2026
Source: NVD
CVE-2026-9627 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely...

Published: May 27, 2026
Source: NVD
CVE-2026-9609 MEDIUM - 4.7

A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem ear...

Published: May 27, 2026
Source: NVD
CVE-2026-9608 LOW - 2.4

A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been public...

Published: May 27, 2026
Source: NVD
CVE-2026-9207 HIGH - 8.8

Tanium addressed an unauthorized code execution vulnerability in Connect.

Vendor: tanium
Product: connect
Published: May 27, 2026
Source: NVD
CVE-2026-9156 MEDIUM - 6.5

Tanium addressed a denial of service vulnerability in Tanium Server.

Vendor: tanium
Product: server
Published: May 27, 2026
Source: NVD
CVE-2026-7493 MEDIUM - 5.3

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function...

Published: May 27, 2026
Source: NVD
CVE-2026-6565 MEDIUM - 6.4

The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient in...

Published: May 27, 2026
Source: NVD

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unrespo...

Vendor: OpenStack
Product: Swift
Published: May 27, 2026
Source: NVD
CVE-2026-49014 HIGH - 7.4

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribu...

Vendor: GDAL
Product: GDAL
Published: May 27, 2026
Source: NVD

@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects

Vendor: npm
Product: @hapi/wreck
Published: May 27, 2026
Source: GitHub

@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters

Vendor: npm
Product: @hapi/content
Published: May 27, 2026
Source: GitHub
CVE-2026-44741 HIGH - 8.8

Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter

Vendor: composer
Product: pimcore/admin-ui-classic-bundle
Published: May 27, 2026
Source: GitHub
CVE-2026-44739 HIGH - 8.7

Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub