Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,981
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 801 - 820 of 3,396 CVEs
CVE-2026-46695 CRITICAL - 10.0

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the director...

Vendor: pip
Product: boxlite
Published: May 21, 2026
Source: GitHub

Twig: PHP code injection via `{% use %}` template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub
CVE-2026-46614 CRITICAL - 9.8

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route β€” /fission-function/<name> and /fission-function/<ns>/<name> β€”...

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-48207 CRITICAL - 9.8

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Pyt...

Vendor: Apache Software Foundation
Product: Apache Fory
Published: May 21, 2026
Source: NVD
CVE-2026-39531 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0.

Vendor: Wp Directory Kit
Product: WP Directory Kit
Published: May 21, 2026
Source: NVD
CVE-2025-71211 CRITICAL - 9.8

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable. Please note: although this vulnerabil...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2025-71210 CRITICAL - 9.8

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via...

Vendor: Trend Micro, Inc.
Product: TrendAI Apex One, TrendAI Apex One as a Service
Published: May 21, 2026
Source: NVD
CVE-2026-5118 CRITICAL - 9.8

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured ...

Published: May 21, 2026
Source: NVD
CVE-2026-5433 CRITICAL - 9.1

Honeywell Control Network Module (CNM)Β contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).

Vendor: honeywell
Product: control_network_module_firmware
Published: May 21, 2026
Source: NVD
CVE-2026-44050 CRITICAL - 9.9

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-6279 CRITICAL - 9.8

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value()` passing attacker-...

Published: May 21, 2026
Source: NVD
CVE-2026-48172 CRITICAL - 9.8

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. LiteSpeed WHM Plugin (the parent plugin) is unaffected. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs...

Vendor: LiteSpeed Technologies
Product: cPanel Plugin
Published: May 21, 2026
Source: NVD
CVE-2026-47372 CRITICAL - 9.1

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

Vendor: RRWO
Product: Crypt::SaltedHash
Published: May 20, 2026
Source: NVD
CVE-2026-8631 CRITICAL - 9.8

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.

Vendor: hp
Product: linux_imaging_and_printing
Published: May 20, 2026
Source: NVD
CVE-2026-9141 CRITICAL - 9.8

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages without any session management or server-side authentication checks. Attackers w...

Published: May 20, 2026
Source: NVD
CVE-2026-9139 CRITICAL - 9.8

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static plaintext credentials in the page source. Unauthentic...

Published: May 20, 2026
Source: NVD
CVE-2026-45444 CRITICAL - 10.0

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

Vendor: WP Swings
Product: Gift Cards For WooCommerce Pro
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without ...

Vendor: xwiki
Product: xwiki-platform
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnera...

Vendor: xwiki
Product: xwiki-commons
Published: May 20, 2026
Source: NVD
CVE-2026-20223 CRITICAL - 10.0

A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role. This vulnerability is due to insufficient validation and authentication wh...

Vendor: Cisco
Product: Cisco Secure Workload
Published: May 20, 2026
Source: NVD