Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,121 - 8,140 of 35,847 CVEs
CVE-2026-44723 MEDIUM - 5.0

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_g...

Vendor: VowpalWabbit
Product: vowpal_wabbit
Published: May 26, 2026
Source: NVD
CVE-2026-44314 MEDIUM - 4.3

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic ...

Vendor: traccar
Product: traccar
Published: May 26, 2026
Source: NVD

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check after joining. A directory of ../../../tmp resolves cleanly to /tmp, outside the web root. This ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not goroutine-safe, concurrent requests race on the shared ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD
CVE-2026-40384 HIGH - 7.5

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-40383 CRITICAL - 9.8

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35223 CRITICAL - 9.8

An improper access check allows unauthorized access to com_config webservice endpoints.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35222 CRITICAL - 9.8

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35221 CRITICAL - 9.8

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35220 MEDIUM - 4.3

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30895 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30894 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the content history component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD

A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API pr...

Published: May 26, 2026
Source: NVD
CVE-2026-25901 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-25900 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the feed modules.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-24212 HIGH - 7.5

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Isaac Launchable
Published: May 26, 2026
Source: NVD
CVE-2026-24162 HIGH - 7.8

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: Merlin Transformers4Rec
Published: May 26, 2026
Source: NVD
CVE-2025-36221 MEDIUM - 5.3

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

Vendor: IBM
Product: Cloud Pak for Data System - Cyclops
Published: May 26, 2026
Source: NVD
CVE-2025-36220 MEDIUM - 4.3

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Vendor: IBM
Product: Cloud Pak for Data System - Cyclops
Published: May 26, 2026
Source: NVD
CVE-2025-36148 MEDIUM - 5.4

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the int...

Vendor: IBM
Product: Financial Transaction Manager for SWIFT Services for Multiplatforms
Published: May 26, 2026
Source: NVD