Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,297
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,361 - 8,380 of 35,847 CVEs
CVE-2026-46745 MEDIUM - 5.3

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authenticat...

Vendor: Apache Software Foundation
Product: Apache Airflow FAB provider
Published: May 25, 2026
Source: NVD

OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSyst...

Vendor: OutSystems
Product: Lifetime
Published: May 25, 2026
Source: NVD
CVE-2026-9446 MEDIUM - 4.7

A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to ...

Published: May 25, 2026
Source: NVD
CVE-2026-9445 MEDIUM - 6.3

A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. T...

Published: May 25, 2026
Source: NVD
CVE-2026-9444 MEDIUM - 4.7

A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. T...

Published: May 25, 2026
Source: NVD
CVE-2026-9443 HIGH - 8.8

A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The manipulation of the argument L2TPUserName leads to buffer overflow. The attack may be initiated remo...

Published: May 25, 2026
Source: NVD
CVE-2026-9442 HIGH - 8.8

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipulation of the argument selSSID can lead to buffer overflow. The attack can be launched remotely. The e...

Published: May 25, 2026
Source: NVD
CVE-2026-9441 MEDIUM - 6.3

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated re...

Published: May 25, 2026
Source: NVD

This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including crypt...

Published: May 25, 2026
Source: NVD
CVE-2026-5223 MEDIUM - 5.3

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io ...

Vendor: rust-lang
Product: cargo
Published: May 25, 2026
Source: NVD
CVE-2026-5222 MEDIUM - 6.5

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credent...

Vendor: rust-lang
Product: cargo
Published: May 25, 2026
Source: NVD
CVE-2026-45361 HIGH - 8.1

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-pr...

Vendor: Apache Software Foundation
Product: Apache Airflow Google provider
Published: May 25, 2026
Source: NVD

A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service t...

Published: May 25, 2026
Source: NVD
CVE-2026-9440 MEDIUM - 6.3

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remote...

Published: May 25, 2026
Source: NVD
CVE-2026-9439 MEDIUM - 6.3

A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Th...

Published: May 25, 2026
Source: NVD
CVE-2026-9438 MEDIUM - 5.4

A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file courseDel.php. The manipulation of the argument ID results in improper control of resource identifiers. The attack may be performed from remote...

Published: May 25, 2026
Source: NVD
CVE-2026-9437 MEDIUM - 6.3

A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlText leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be ...

Published: May 25, 2026
Source: NVD
CVE-2026-9436 CRITICAL - 9.8

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be execute...

Published: May 25, 2026
Source: NVD
CVE-2026-9435 CRITICAL - 9.8

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of th...

Published: May 25, 2026
Source: NVD
CVE-2026-4915 MEDIUM - 6.5

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of service (server process termination) via a crafte...

Vendor: mattermost
Product: mattermost_server
Published: May 25, 2026
Source: NVD