Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

831
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 801 - 820 of 27,228 CVEs
CVE-2026-42822 CRITICAL - 10.0

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_local
Published: May 18, 2026
Source: NVD
CVE-2026-32849 MEDIUM - 5.5

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_l...

Vendor: NetBSD
Product: src
Published: May 18, 2026
Source: NVD
CVE-2026-32848 MEDIUM - 4.7

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mu...

Vendor: NetBSD
Product: src
Published: May 18, 2026
Source: NVD
CVE-2026-29965 MEDIUM - 6.1

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscated JavaScript syntax.

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-29964 MEDIUM - 6.1

HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript syntax. The endpoint reflects unsanitized user input in HTTP responses without adequate output ...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-29963 HIGH - 7.5

HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this fl...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-29962 HIGH - 7.5

HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, ...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2023-24215 CRITICAL - 9.1

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.

Published: May 18, 2026
Source: NVD
CVE-2026-45678 HIGH - 7.5

OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45679 MEDIUM - 6.5

OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45676 MEDIUM - 5.5

OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45031 MEDIUM - 5.3

ImageMagick: Policy Bypass in PSD decoder

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-42306 HIGH - 7.2

Docker: Race condition in docker cp allows bind mount redirection to host path

Vendor: go
Product: github.com/docker/docker
Published: May 18, 2026
Source: GitHub
CVE-2026-41568 MEDIUM - 6.1

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

Vendor: go
Product: github.com/docker/docker
Published: May 18, 2026
Source: GitHub

CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion

Vendor: pip
Product: cloakbrowser
Published: May 18, 2026
Source: GitHub
CVE-2026-45358 MEDIUM - 5.3

ImageMagick: Out-of-Bounds Read of a single byte in meta encoder

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45359 MEDIUM - 5.7

ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45719 MEDIUM - 6.5

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

Vendor: npm
Product: @budibase/server
Published: May 18, 2026
Source: GitHub
CVE-2026-41567 HIGH - 7.2

Docker: `PUT /containers/{id}/archive` executes container binary on the host

Vendor: go
Product: github.com/moby/moby/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45718 MEDIUM - 5.4

Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows

Vendor: npm
Product: budibase
Published: May 18, 2026
Source: GitHub