Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,788
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 9,101 - 9,120 of 36,778 CVEs
CVE-2026-41917 MEDIUM - 4.9

OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with action=Load. Attackers can ...

Vendor: Openkm
Product: OpenKM Community Edition, OpenKM Professional Edition
Published: May 26, 2026
Source: NVD
CVE-2026-41401 MEDIUM - 6.5

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadat...

Vendor: libyang
Product: libyang
Published: May 26, 2026
Source: NVD
CVE-2026-40034 HIGH - 7.8

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attack...

Vendor: gitoxide
Product: gitoxide
Published: May 26, 2026
Source: NVD
CVE-2026-40033 HIGH - 8.8

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry d...

Vendor: FreeRDP
Product: FreeRDP
Published: May 26, 2026
Source: NVD
CVE-2026-9544 HIGH - 7.3

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to...

Published: May 26, 2026
Source: NVD
CVE-2026-9543 CRITICAL - 9.8

A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The...

Published: May 26, 2026
Source: NVD
CVE-2026-9542 MEDIUM - 6.3

A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit has been made available...

Published: May 26, 2026
Source: NVD
CVE-2026-9541 MEDIUM - 5.3

A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been re...

Vendor: squirrel-lang
Product: squirrel
Published: May 26, 2026
Source: NVD
CVE-2026-9540 MEDIUM - 5.3

A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The...

Published: May 26, 2026
Source: NVD

IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in bidirectional mode (BCI) is conf...

Published: May 26, 2026
Source: NVD
CVE-2026-8174 MEDIUM - 5.7

Zohocorp Zoho Mail wordpress plugin is vulnerable toΒ Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.

Published: May 26, 2026
Source: NVD
CVE-2026-7374 CRITICAL - 9.9

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink ...

Published: May 26, 2026
Source: NVD

A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful expl...

Published: May 26, 2026
Source: NVD
CVE-2026-48136 MEDIUM - 4.1

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions...

Vendor: checkpoint
Product: Quantum Security Management
Published: May 26, 2026
Source: NVD
CVE-2026-48135 MEDIUM - 5.3

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48134 HIGH - 7.6

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to...

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48133 HIGH - 7.5

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48132 HIGH - 7.4

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negot...

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2026-48131 HIGH - 8.1

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).

Vendor: checkpoint
Product: Quantum Security Gateway
Published: May 26, 2026
Source: NVD
CVE-2025-11482 HIGH - 7.5

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attacker to permanently prevent legitimate users from interacting with the service.

Vendor: B&R Industrial Automation GmbH
Product: PPT30 Operating System
Published: May 26, 2026
Source: NVD