Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,709
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 8,761 - 8,780 of 36,556 CVEs
CVE-2026-8854 HIGH - 7.5

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8835 HIGH - 7.3

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8834 HIGH - 8.0

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8633 CRITICAL - 9.8

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.

Vendor: ibm
Product: websphere_application_server
Published: May 26, 2026
Source: NVD
CVE-2026-8620 HIGH - 7.5

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.

Vendor: ibm
Product: websphere_application_server
Published: May 26, 2026
Source: NVD
CVE-2026-7454 HIGH - 7.8

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7453 MEDIUM - 5.3

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7452 HIGH - 7.8

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7451 HIGH - 7.8

A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7450 MEDIUM - 5.3

A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Vendor: autodesk
Product: 3ds_max
Published: May 26, 2026
Source: NVD
CVE-2026-7251 CRITICAL - 9.8

Eppendorf BioFlo 320Β is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have ful...

Published: May 26, 2026
Source: NVD
CVE-2026-48696 MEDIUM - 6.2

FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48695 HIGH - 8.1

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() c...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48694 HIGH - 8.1

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is directly interpolated into Juniper NETCONF set-configuration commands...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnerability is fixed in 0.9.0.2.

Vendor: Kareadita
Product: Kavita
Published: May 26, 2026
Source: NVD
CVE-2026-46624 CRITICAL - 9.9

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any authenticated user can execute arbitrary OS commands on the ...

Vendor: twentyhq
Product: twenty
Published: May 26, 2026
Source: NVD

Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user who knows or guesses a chapterId, volumeId, or seriesId belonging to a library they are not assigned to can download t...

Vendor: Kareadita
Product: Kavita
Published: May 26, 2026
Source: NVD

Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from any chapter in any library. While the endpoint accepts an apiKey parameter, it is never validated. Sinc...

Vendor: Kareadita
Product: Kavita
Published: May 26, 2026
Source: NVD
CVE-2026-44749 MEDIUM - 4.3

The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.

Vendor: SAP_SE
Product: SAP Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-44730 HIGH - 7.2

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their own organization. This is due to incorrect ACL on u...

Vendor: OpenCTI-Platform
Product: opencti
Published: May 26, 2026
Source: NVD