Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,879
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 901 - 920 of 3,396 CVEs
CVE-2026-45374 CRITICAL - 9.6

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) and auto_approve defaults to true (task_manager.rs:297: auto_ap...

Vendor: rust
Product: deepseek-tui
Published: May 14, 2026
Source: GitHub
CVE-2026-45311 CRITICAL - 9.6

CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and executes arbitrary code: test binaries, build.rs build scri...

Vendor: rust
Product: deepseek-tui
Published: May 14, 2026
Source: GitHub
CVE-2026-8634 CRITICAL - 9.1

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit ove...

Published: May 14, 2026
Source: NVD
CVE-2026-8580 CRITICAL - 9.6

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 14, 2026
Source: NVD
CVE-2026-8511 CRITICAL - 9.6

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 14, 2026
Source: NVD

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/Web...

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub
CVE-2026-44592 CRITICAL - 9.4

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker without any credentials by sending a fresh, never-registered worker UUID. The resulting session has PeerA...

Vendor: wavelens
Product: gradient
Published: May 14, 2026
Source: NVD
CVE-2026-44990 CRITICAL - 9.3

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML o...

Vendor: npm
Product: sanitize-html
Published: May 14, 2026
Source: GitHub
CVE-2026-41615 CRITICAL - 9.6

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: authenticator
Published: May 14, 2026
Source: NVD
CVE-2026-20182 CRITICAL - 10.0

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Contr...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: May 14, 2026
Source: NVD
CVE-2026-44849 CRITICAL - 8.8

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer enforces seven EndpointSecuritySettings restrictions that admin...

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44848 CRITICAL - 8.8

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, The Docker plugin management endpoints (/plugins/*) were not registered w...

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

n8n Has an XML Node Prototype Pollution Patch Bypass

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has an Arbitrary File Read via Git Node

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44482 CRITICAL - 9.6

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the...

Vendor: richardhbtz
Product: soundcloud-rpc
Published: May 14, 2026
Source: NVD
CVE-2026-42457 CRITICAL - 9.0

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scr...

Vendor: loft-sh
Product: loft
Published: May 14, 2026
Source: NVD
CVE-2026-27886 CRITICAL - 7.5

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An unauthenticated attacker could use the `where` query parameter on any publicly-accessible...

Vendor: npm
Product: @strapi/strapi
Published: May 14, 2026
Source: GitHub
CVE-2026-2347 CRITICAL - 9.8

Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001.

Published: May 14, 2026
Source: NVD
CVE-2025-11024 CRITICAL - 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. This issue affects E-Commerce Website: before 4.5.001.

Vendor: Akilli Commerce Software Technologies Ltd. Co.
Product: E-Commerce Website
Published: May 14, 2026
Source: NVD