Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,815
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,261 - 8,280 of 36,689 CVEs

RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that inc...

Vendor: rabbitmq
Product: rabbitmq-server
Published: May 27, 2026
Source: NVD

Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, the BearerTokenAuthMiddleware bypasses authentication for all HTTP requests. Combined with the default 0.0.0.0 host binding and CORS allow_origins=[&qu...

Vendor: Dataojitori
Product: nocturne_memory
Published: May 27, 2026
Source: NVD
CVE-2026-37713 HIGH - 7.3

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.

Published: May 27, 2026
Source: NVD
CVE-2026-37712 HIGH - 7.3

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in function job type

Published: May 27, 2026
Source: NVD
CVE-2026-37711 HIGH - 7.3

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php

Published: May 27, 2026
Source: NVD
CVE-2026-31266 HIGH - 7.3

Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).

Published: May 27, 2026
Source: NVD
CVE-2026-30498 MEDIUM - 6.3

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.

Published: May 27, 2026
Source: NVD
CVE-2026-1248 MEDIUM - 4.3

IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.

Vendor: ibm
Product: business_automation_workflow
Published: May 27, 2026
Source: NVD
CVE-2025-70103 HIGH - 7.3

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

Published: May 27, 2026
Source: NVD
CVE-2026-9704 MEDIUM - 6.8

A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client cre...

Vendor: redhat
Product: build_of_keycloak
Published: May 27, 2026
Source: NVD
CVE-2026-9617 MEDIUM - 6.8

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-anonymity function, the malicious code is executed with superuser privileges. The risk is higher with P...

Vendor: dalibo
Product: anonymizer
Published: May 27, 2026
Source: NVD
CVE-2026-9035 MEDIUM - 6.5

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able ...

Published: May 27, 2026
Source: NVD
CVE-2026-8405 MEDIUM - 6.5

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.

Vendor: ibm
Product: guardium_data_protection
Published: May 27, 2026
Source: NVD
CVE-2026-8180 HIGH - 7.5

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause th...

Published: May 27, 2026
Source: NVD
CVE-2026-8179 HIGH - 8.8

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated ...

Published: May 27, 2026
Source: NVD
CVE-2026-8175 CRITICAL - 9.8

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a...

Published: May 27, 2026
Source: NVD
CVE-2026-7876 CRITICAL - 9.1

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19

Vendor: ibm
Product: aspera_high-speed_transfer_server_for_cloud_pak_for_integration
Published: May 27, 2026
Source: NVD
CVE-2026-7528 HIGH - 7.1

IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.

Vendor: langflow
Product: langflow
Published: May 27, 2026
Source: NVD
CVE-2026-7524 CRITICAL - 9.8

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

Vendor: langflow
Product: langflow
Published: May 27, 2026
Source: NVD
CVE-2026-7365 HIGH - 8.4

IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

Vendor: ibm
Product: operations_analytics_log_analysis
Published: May 27, 2026
Source: NVD