Total CVEs

139,961

Critical Severity

3,664

High Severity

13,210

Last 7 Days

1,617
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,121 - 9,140 of 36,366 CVEs
CVE-2026-8347 MEDIUM - 4.3

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The...

Vendor: concretecms
Product: concrete_cms
Published: May 22, 2026
Source: NVD
CVE-2026-8340 MEDIUM - 4.3

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor's unpublished versi...

Vendor: concretecms
Product: concrete_cms
Published: May 22, 2026
Source: NVD
CVE-2025-46371 MEDIUM - 5.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-45145 HIGH - 7.5

Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter

Published: May 22, 2026
Source: NVD
CVE-2025-32751 MEDIUM - 5.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2021-21508 MEDIUM - 6.7

Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable applicat...

Published: May 22, 2026
Source: NVD
CVE-2026-9277 HIGH - 8.1

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.o...

Vendor: npm
Product: shell-quote
Published: May 22, 2026
Source: NVD

vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the hist...

Published: May 22, 2026
Source: NVD
CVE-2026-8673 MEDIUM - 5.9

Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2026-8672 MEDIUM - 5.1

Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2026-8671 HIGH - 7.5

Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2026-8670 CRITICAL - 9.6

Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This issue affects Avantra: before 25.3.1.

Published: May 22, 2026
Source: NVD
CVE-2025-32749 HIGH - 7.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-32747 HIGH - 7.8

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-32746 MEDIUM - 5.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-32745 MEDIUM - 6.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-26483 HIGH - 8.2

Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to con...

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2026-44930 CRITICAL - 9.8

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Vendor: apache
Product: cxf
Published: May 22, 2026
Source: NVD
CVE-2026-44618 MEDIUM - 5.3

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Vendor: apache
Product: cxf
Published: May 22, 2026
Source: NVD
CVE-2026-44417 HIGH - 7.5

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, ...

Vendor: apache
Product: cxf
Published: May 22, 2026
Source: NVD