Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 9,281 - 9,300 of 36,556 CVEs
CVE-2026-34207 HIGH - 7.6

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It does not resolve DNS before allowing the request. As a result, a hostname such as ssrf-repro.example ...

Published: May 22, 2026
Source: NVD
CVE-2026-33712 CRITICAL - 10.0

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch...

Published: May 22, 2026
Source: NVD
CVE-2026-32253 CRITICAL - 9.8

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOC...

Vendor: lizardbyte
Product: sunshine
Published: May 22, 2026
Source: NVD
CVE-2026-28735 MEDIUM - 5.4

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub author...

Vendor: mattermost
Product: mattermost_server
Published: May 22, 2026
Source: NVD
CVE-2026-28445 HIGH - 8.7

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML directive without any sanitization, even though DOMPurify is already a dependency and is used elsewher...

Vendor: npm
Product: @typebot.io/js
Published: May 22, 2026
Source: NVD
CVE-2026-28444 MEDIUM - 6.5

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verifying that the result belongs to the authorized typebot, leading to IDOR. An authenticated attacker can...

Published: May 22, 2026
Source: NVD
CVE-2026-9251 MEDIUM - 5.4

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's data via a crafted status change request. This issue affects : * Devolut...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9249 LOW - 3.1

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9248 LOW - 2.6

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request. This issue affects : * Devolutions Server 2026.1....

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9247 LOW - 2.4

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This issue affects : * Devolutions Server 2026.1.6.0 th...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9246 MEDIUM - 4.3

Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 th...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9245 MEDIUM - 5.0

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Dev...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9224 MEDIUM - 4.3

Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3....

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9223 MEDIUM - 4.3

Missing authorization in the vault import feature in Devolutions ServerΒ Β 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-9047 HIGH - 7.6

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * D...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-8477 LOW - 2.7

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed entry to retrieve its sensitive data without triggering the unseal audit notification via a crafted API request. This issue affe...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-7325 HIGH - 7.1

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects : ...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-5171 MEDIUM - 4.3

Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 th...

Vendor: devolutions
Product: devolutions_server
Published: May 22, 2026
Source: NVD
CVE-2026-42506 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-42502 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD