Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

825
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 821 - 840 of 27,228 CVEs
CVE-2026-45716 HIGH - 8.8

Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration

Vendor: npm
Product: @budibase/worker
Published: May 18, 2026
Source: GitHub
CVE-2026-45707 HIGH - 8.1

n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub

Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens

Vendor: composer
Product: sulu/sulu
Published: May 18, 2026
Source: GitHub
CVE-2026-45363 HIGH - 7.4

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

Vendor: rubygems
Product: jwt
Published: May 18, 2026
Source: GitHub
CVE-2026-45697 CRITICAL - 9.8

Formie: Pre-authenticated server-side template injection in Hidden fields

Vendor: composer
Product: verbb/formie
Published: May 18, 2026
Source: GitHub
CVE-2026-45327 HIGH - 8.2

TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection

Vendor: go
Product: github.com/DatanoiseTV/tinyice
Published: May 18, 2026
Source: GitHub
CVE-2026-8843 MEDIUM - 6.5

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "queryable_encrypted_range" indices. This issue a...

Published: May 18, 2026
Source: NVD

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in theΒ /api/v2/tenants/{tenant}/databases/{db}/...

Vendor: Chroma
Product: ChromaDB
Published: May 18, 2026
Source: NVD
CVE-2026-41085 HIGH - 8.8

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces.

Published: May 18, 2026
Source: NVD
CVE-2026-38719 MEDIUM - 6.2

OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF message can supply an attacker-controlled item_count value that is not consistently v...

Published: May 18, 2026
Source: NVD
CVE-2026-45325 HIGH - 8.2

@tmlmobilidade/utils has prototype pollution in its setValueAtPath

Vendor: npm
Product: @tmlmobilidade/utils
Published: May 18, 2026
Source: GitHub
CVE-2026-45302 HIGH - 8.2

parse-nested-form-data has Prototype Pollution via `__proto__` in FormData field names

Vendor: npm
Product: parse-nested-form-data
Published: May 18, 2026
Source: GitHub
CVE-2026-45300 HIGH - 7.4

async-http-client: Cookie header not stripped on cross-origin redirect

Vendor: maven
Product: org.asynchttpclient:async-http-client
Published: May 18, 2026
Source: GitHub
CVE-2026-45298 HIGH - 8.6

Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)

Vendor: go
Product: github.com/amir20/dozzle
Published: May 18, 2026
Source: GitHub
CVE-2026-46385 HIGH - 7.5

iskorotkov/avro: CPU Exhaustion in Decoder

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45270 HIGH - 8.7

CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-46384 HIGH - 7.5

iskorotkov/avro: Integer Overflow in Decoder

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45149 MEDIUM - 6.5

brace-expansion: Large numeric range defeats documented `max` DoS protection

Vendor: npm
Product: brace-expansion
Published: May 18, 2026
Source: GitHub
CVE-2026-45139 MEDIUM - 6.5

CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-36438 MEDIUM - 5.3

An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd

Published: May 18, 2026
Source: NVD