Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,161 - 8,180 of 36,689 CVEs
CVE-2026-47274 MEDIUM - 6.3

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb helper tools resolved external binaries through the PATH environment variable rather than using absolute paths. An attacker who can influence the process environment during PAM authent...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-47273 MEDIUM - 6.5

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath expressions from user-supplied identifiers (PAM username, service name) and device-supplied identifiers (USB device serial, model, vendor) to query /etc/pamusb.conf. These identifi...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-47272 HIGH - 7.1

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) could be read, but did not enforce that the system-side pad (the pad file on the USB device) was...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-47271 MEDIUM - 5.1

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented out-of-memory guards for xmalloc(), xrealloc(), and xstrdup() using assert(data != NULL). The C standard specifies that all assert() expressions are compiled out when NDEBUG is de...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD

RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker who can reach the message broker can execute arbitrary commands on the host server. Co...

Vendor: inducer
Product: relate
Published: May 27, 2026
Source: NVD
CVE-2026-45108 HIGH - 8.4

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability in the Device Authorization Grant (DAG) flow that allowed a user within the same Entra ID domain to obtain a local Unix ...

Vendor: himmelblau-idm
Product: himmelblau
Published: May 27, 2026
Source: NVD
CVE-2026-45104 HIGH - 7.5

MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> โ€” it assumes msSLDParseRule added one class. When the rule has no symbolizer (a str...

Vendor: MapServer
Product: MapServer
Published: May 27, 2026
Source: NVD
CVE-2026-45102 CRITICAL - 9.9

OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive. This API was not designed for that and can be escaped via error objects and infinite recursion. This vulnerability is fixed in 10.0.98.

Vendor: OneUptime
Product: oneuptime
Published: May 27, 2026
Source: NVD
CVE-2026-44888 CRITICAL - 9.8

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly into pialert.conf without validation. Since pialert.conf is loaded via Python's exec() eve...

Vendor: leiweibau
Product: Pi.Alert
Published: May 27, 2026
Source: NVD
CVE-2026-44887 CRITICAL - 9.8

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. Since the background scan daemon loads this file via Python's exec(), injected code executes...

Vendor: leiweibau
Product: Pi.Alert
Published: May 27, 2026
Source: NVD

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devices.php route accepts requests from unauthenticated users when the action URL parameter is set to get...

Vendor: leiweibau
Product: Pi.Alert
Published: May 27, 2026
Source: NVD
CVE-2026-44590 CRITICAL - 9.3

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltr...

Vendor: sherlock-project
Product: sherlock
Published: May 27, 2026
Source: NVD
CVE-2026-42197 HIGH - 8.7

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's browser session, potentially leading to full admin ...

Vendor: inducer
Product: relate
Published: May 27, 2026
Source: NVD

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

Published: May 27, 2026
Source: NVD

Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification

Vendor: composer
Product: symfony/html-sanitizer
Published: May 27, 2026
Source: GitHub

Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters โ†’ Visual href Spoofing

Vendor: composer
Product: symfony/html-sanitizer
Published: May 27, 2026
Source: GitHub
CVE-2026-44982 HIGH - 7.2

CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests

Vendor: go
Product: github.com/crowdsecurity/crowdsec
Published: May 27, 2026
Source: GitHub

CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression

Vendor: go
Product: github.com/crowdsecurity/crowdsec
Published: May 27, 2026
Source: GitHub
CVE-2026-44726 HIGH - 7.4

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attemp...

Vendor: rust
Product: deno
Published: May 27, 2026
Source: GitHub
CVE-2026-25879 CRITICAL - 9.8

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e....

Vendor: pip
Product: langroid
Published: May 27, 2026
Source: GitHub