Total CVEs

139,961

Critical Severity

3,664

High Severity

13,210

Last 7 Days

1,617
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,101 - 9,120 of 36,366 CVEs
CVE-2026-9246 MEDIUM - 4.3

Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 th...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9245 MEDIUM - 5.0

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Dev...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9224 MEDIUM - 4.3

Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3....

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9223 MEDIUM - 4.3

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9047 HIGH - 7.6

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * D...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-8477 LOW - 2.7

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed entry to retrieve its sensitive data without triggering the unseal audit notification via a crafted API request. This issue affe...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-7325 HIGH - 7.1

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects : ...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-5171 MEDIUM - 4.3

Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 th...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-42506 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-42502 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-39821 CRITICAL - 10.0

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program...

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-27136 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-25681 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-25680 MEDIUM - 6.5

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2022-34363 MEDIUM - 6.5

Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX application running in vApp

Vendor: dell
Product: unisphere_for_powermax_virtual_appliance
Published: May 22, 2026
Source: NVD
CVE-2022-31231 HIGH - 7.5

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.

Vendor: dell
Product: elastic_cloud_storage
Published: May 22, 2026
Source: NVD
CVE-2026-46670 CRITICAL - 9.8

YesWiki: Unauthenticated SQL Injection

Vendor: composer
Product: yeswiki/yeswiki
Published: May 22, 2026
Source: GitHub
CVE-2026-9256 HIGH - 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that re...

Published: May 22, 2026
Source: NVD
CVE-2026-8992 HIGH - 8.8

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

Vendor: ivanti
Product: secure_access_client
Published: May 22, 2026
Source: NVD
CVE-2026-8353 MEDIUM - 4.8

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious ...

Vendor: concretecms
Product: concrete_cms
Published: May 22, 2026
Source: NVD