Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,821 - 8,840 of 36,556 CVEs
CVE-2026-48126 HIGH - 8.2

Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the value of the client-s...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD

Rejected reason: Further research determined the issue is not a vulnerability.

Published: May 26, 2026
Source: NVD
CVE-2026-47728 MEDIUM - 4.3

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one project could cause event processing in that project to use sour...

Vendor: bugsink
Product: bugsink
Published: May 26, 2026
Source: NVD

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, but applies the requested bulk action to the submitted issue IDs without also requiring those issues to belong to that project. This vulnerability...

Vendor: bugsink
Product: bugsink
Published: May 26, 2026
Source: NVD

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up that event without also requiring it to belong to the issue in the URL. This is a project-boundary authorization issue: a logged-in...

Vendor: bugsink
Product: bugsink
Published: May 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().

Vendor: Linux
Product: Linux
Published: May 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().

Vendor: Linux
Product: Linux
Published: May 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().

Vendor: Linux
Product: Linux
Published: May 26, 2026
Source: NVD
CVE-2026-44729 HIGH - 8.7

Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authen...

Vendor: twentyhq
Product: twenty
Published: May 26, 2026
Source: NVD
CVE-2026-44723 MEDIUM - 5.0

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_g...

Vendor: VowpalWabbit
Product: vowpal_wabbit
Published: May 26, 2026
Source: NVD
CVE-2026-44314 MEDIUM - 4.3

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic ...

Vendor: traccar
Product: traccar
Published: May 26, 2026
Source: NVD

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check after joining. A directory of ../../../tmp resolves cleanly to /tmp, outside the web root. This ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not goroutine-safe, concurrent requests race on the shared ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD
CVE-2026-40384 HIGH - 7.5

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-40383 CRITICAL - 9.8

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35223 CRITICAL - 9.8

An improper access check allows unauthorized access to com_config webservice endpoints.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35222 CRITICAL - 9.8

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35221 CRITICAL - 9.8

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35220 MEDIUM - 4.3

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30895 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD