Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,944
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 821 - 840 of 3,396 CVEs
CVE-2026-8598 CRITICAL - 9.1

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.

Published: May 20, 2026
Source: NVD

Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)

Vendor: npm
Product: @cap-js/sqlite
Published: May 20, 2026
Source: GitHub

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler in 'Elixir.PhoenixStorybook.Story.PlaygroundPreviewLive':handle_ev...

Vendor: erlang
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD
CVE-2026-22314 CRITICAL - 9.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems.Β This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Ser...

Vendor: Mesalvo
Product: Meona Client Launcher Component, Meona Server Component
Published: May 20, 2026
Source: NVD
CVE-2026-42960 CRITICAL - 10.0

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such recor...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-33278 CRITICAL - 9.8

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vuln...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-7637 CRITICAL - 9.8

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in...

Published: May 20, 2026
Source: NVD
CVE-2026-24207 CRITICAL - 9.8

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-7284 CRITICAL - 9.8

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can reg...

Published: May 20, 2026
Source: NVD
CVE-2026-6555 CRITICAL - 9.8

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and upl...

Published: May 20, 2026
Source: NVD
CVE-2026-8495 CRITICAL - 9.8

Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.

Published: May 19, 2026
Source: NVD
CVE-2026-34234 CRITICAL - 10.0

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler f...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2026-46412 CRITICAL - 10.0

Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) β€” Mini Shai-Hulud worm

Vendor: npm
Product: @beproduct/nestjs-auth
Published: May 19, 2026
Source: GitHub
CVE-2026-46354 CRITICAL - 9.1

Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft

Vendor: go
Product: github.com/coder/coder/v2
Published: May 19, 2026
Source: GitHub
CVE-2026-46339 CRITICAL - 10.0

9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

Vendor: npm
Product: 9router
Published: May 19, 2026
Source: GitHub
CVE-2026-45695 CRITICAL - 9.8

Kopia: RCE via SSH ProxyCommand Injection

Vendor: go
Product: github.com/kopia/kopia
Published: May 19, 2026
Source: GitHub
CVE-2026-33642 CRITICAL - 9.9

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/W...

Vendor: kovidgoyal
Product: kitty
Published: May 19, 2026
Source: NVD
CVE-2026-8605 CRITICAL - 9.8

In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8603 CRITICAL - 9.8

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8602 CRITICAL - 9.1

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD