Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,503
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,101 - 9,120 of 36,830 CVEs

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().

Vendor: Linux
Product: Linux
Published: May 26, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume_cb() and l2cap_sock_ready_cb().

Vendor: Linux
Product: Linux
Published: May 26, 2026
Source: NVD
CVE-2026-44729 HIGH - 8.7

Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authen...

Vendor: twentyhq
Product: twenty
Published: May 26, 2026
Source: NVD
CVE-2026-44723 MEDIUM - 5.0

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_g...

Vendor: VowpalWabbit
Product: vowpal_wabbit
Published: May 26, 2026
Source: NVD
CVE-2026-44314 MEDIUM - 4.3

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into mediaManager.createFileStream(...). Unlike the generic ...

Vendor: traccar
Product: traccar
Published: May 26, 2026
Source: NVD

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check after joining. A directory of ../../../tmp resolves cleanly to /tmp, outside the web root. This ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not goroutine-safe, concurrent requests race on the shared ...

Vendor: xyproto
Product: algernon
Published: May 26, 2026
Source: NVD
CVE-2026-40384 HIGH - 7.5

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-40383 CRITICAL - 9.8

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35223 CRITICAL - 9.8

An improper access check allows unauthorized access to com_config webservice endpoints.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35222 CRITICAL - 9.8

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35221 CRITICAL - 9.8

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-35220 MEDIUM - 4.3

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30895 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-30894 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the content history component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD

A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API pr...

Published: May 26, 2026
Source: NVD
CVE-2026-25901 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the multilingual associations component.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-25900 MEDIUM - 6.1

Lack of output escaping leads to a XSS vector in the feed modules.

Vendor: Joomla! Project
Product: Joomla! CMS
Published: May 26, 2026
Source: NVD
CVE-2026-24212 HIGH - 7.5

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Isaac Launchable
Published: May 26, 2026
Source: NVD
CVE-2026-24162 HIGH - 7.8

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: Merlin Transformers4Rec
Published: May 26, 2026
Source: NVD