Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,916
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 881 - 900 of 3,396 CVEs
CVE-2026-7302 CRITICAL - 9.1

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD
CVE-2026-7301 CRITICAL - 9.8

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD
CVE-2026-8721 CRITICAL - 9.8

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on t...

Published: May 17, 2026
Source: NVD
CVE-2026-8507 CRITICAL - 9.8

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution pote...

Published: May 17, 2026
Source: NVD
CVE-2018-25335 CRITICAL - 9.8

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter ...

Vendor: peugeot-music-plugin
Product: Peugeot Music
Published: May 17, 2026
Source: NVD
CVE-2018-25332 CRITICAL - 9.8

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality. Attackers can brute-force the Blowfish encryption key, upload a malicious JAR plugin...

Vendor: gitbucket
Product: GitBucket
Published: May 17, 2026
Source: NVD
CVE-2018-25320 CRITICAL - 9.8

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to est...

Vendor: acl
Product: ACL Analytics
Published: May 17, 2026
Source: NVD
CVE-2021-47952 CRITICAL - 9.8

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deseria...

Vendor: Jsonpickle
Product: python jsonpickle
Published: May 16, 2026
Source: NVD
CVE-2020-37239 CRITICAL - 9.8

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwri...

Vendor: Gegl
Product: libbabl
Published: May 16, 2026
Source: NVD
CVE-2020-37228 CRITICAL - 9.8

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against u...

Vendor: Yerootech
Product: iDS6 DSSPro Digital Signage System
Published: May 16, 2026
Source: NVD
CVE-2026-46364 CRITICAL - 9.8

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/capt...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-45010 CRITICAL - 9.1

phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts arbitrary user-id parameters without session binding or rate limiting. Unauthenticated attackers can brute-force any user's six-digit TOTP code b...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2021-47965 CRITICAL - 9.8

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code ...

Vendor: wp-super-edit
Product: WP Super Edit
Published: May 15, 2026
Source: NVD
CVE-2026-44717 CRITICAL - 9.8

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.

Vendor: 611711Dark
Product: mcp_calculate_server
Published: May 15, 2026
Source: NVD
CVE-2026-45772 CRITICAL - 9.8

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package manager detection exe...

Vendor: vercel, @turbo
Product: turborepo, codemod, workspaces
Published: May 15, 2026
Source: NVD
CVE-2026-41553 CRITICAL - 10.0

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequent...

Vendor: DHTMLX
Product: PDF Export Module
Published: May 15, 2026
Source: NVD
CVE-2026-8398 CRITICAL - 9.8

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vend...

Published: May 15, 2026
Source: NVD
CVE-2026-5229 CRITICAL - 9.8

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email ad...

Published: May 15, 2026
Source: NVD
CVE-2026-45288 CRITICAL - 9.8

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to u...

Vendor: nuget
Product: Marten
Published: May 14, 2026
Source: GitHub
CVE-2026-45353 CRITICAL - 7.8

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub