Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,766
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,721 - 8,740 of 36,556 CVEs

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetched server-side without any URL validation or internal IP filtering. This vulnerability is fixed in 2...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD
CVE-2026-44847 HIGH - 7.5

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns (None, {}), which Django REST Framework interprets as successful authe...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD
CVE-2026-44451 CRITICAL - 9.3

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSou...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44450 CRITICAL - 9.9

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution ...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44449 CRITICAL - 9.1

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename is concatenated directly into the smbclient -c script without validation. smbcli...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44444 CRITICAL - 9.1

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json with a preinstall, posti...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44443 MEDIUM - 4.8

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's auth.api.signUpEmail() ca...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The endpoint uses application_id from the URL path without validating ownership, allowing attackers to perf...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access in...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD

MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch (chat/api/oss/get_url) endpoint. The vulnerability exists due to inconsistent URL parsing between the urlparse v...

Vendor: 1Panel-dev
Product: MaxKB
Published: May 26, 2026
Source: NVD
CVE-2026-36239 MEDIUM - 4.3

PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

Published: May 26, 2026
Source: NVD

AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interfac...

Published: May 26, 2026
Source: NVD

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation throug...

Published: May 26, 2026
Source: NVD
CVE-2025-14361 HIGH - 7.1

Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1.

Vendor: AA-Team
Product: Woocommerce Envato Affiliates
Published: May 26, 2026
Source: NVD
CVE-2026-48048 HIGH - 7.5

XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests

Vendor: maven
Product: org.xwiki.platform:xwiki-platform-livetable-ui
Published: May 26, 2026
Source: GitHub
CVE-2026-9575 HIGH - 7.3

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has ...

Published: May 26, 2026
Source: NVD
CVE-2026-9574 HIGH - 7.3

A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the argument studentId/cid can lead to sql injection. The attack can be launched remotely. The exploit has...

Published: May 26, 2026
Source: NVD
CVE-2026-9573 HIGH - 7.3

A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation of the argument studentId results in sql injection. The attack can be initiated remotely. The exploit ...

Published: May 26, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 26, 2026
Source: NVD
CVE-2026-27331 MEDIUM - 6.3

Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.

Vendor: Magepeople inc.
Product: WpTravelly
Published: May 26, 2026
Source: NVD