Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,801 - 8,820 of 36,556 CVEs
CVE-2026-9565 MEDIUM - 6.3

A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handler. Executing a manipulation can lead to os command injection. The attack can be executed remotely. Th...

Published: May 26, 2026
Source: NVD
CVE-2026-9564 LOW - 2.4

A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Performing a manipulation of the argument Remarks results in cross site scripting. Remote exploitation of...

Published: May 26, 2026
Source: NVD
CVE-2026-9562 HIGH - 7.3

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been...

Published: May 26, 2026
Source: NVD
CVE-2026-8852 MEDIUM - 6.2

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-8850 HIGH - 7.5

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.

Vendor: ibm
Product: http_server
Published: May 26, 2026
Source: NVD
CVE-2026-48905 MEDIUM - 6.1

Lack of input filtering leads to an XSS vector in the HTML filter code.

Vendor: Joomla! Project
Product: Joomla! Framework Filter package
Published: May 26, 2026
Source: NVD
CVE-2026-48904 CRITICAL - 9.8

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48903 MEDIUM - 6.1

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

Vendor: Joomla! Project
Product: Joomla! Framework Filter package
Published: May 26, 2026
Source: NVD
CVE-2026-48902 CRITICAL - 9.8

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48901 HIGH - 7.5

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48900 MEDIUM - 4.3

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48899 CRITICAL - 9.8

An improper access check allows privilege escalation through the com_users batch task.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48898 CRITICAL - 9.8

An improper access check allows privilege escalation through the com_users batch task.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48897 HIGH - 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48896 HIGH - 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-48864 HIGH - 7.8

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can le...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, Red Hat Update Infrastructure 4 for Cloud Providers
Published: May 26, 2026
Source: NVD
CVE-2026-48697 HIGH - 7.4

FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but neve...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48693 MEDIUM - 5.5

FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The print_screen_contents_into_file() function (src/fastnetmon_logic.cpp line 218...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48691 CRITICAL - 9.8

FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segment_element_t) + this->as_path_asns.size() * sizeof(u...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-48690 HIGH - 7.1

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(fastnetmon_pcap_...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD