Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,301 - 9,320 of 36,556 CVEs
CVE-2026-39821 CRITICAL - 10.0

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program...

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-27136 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-25681 MEDIUM - 6.1

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-25680 MEDIUM - 6.5

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2022-34363 MEDIUM - 6.5

Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX application running in vApp

Vendor: dell
Product: unisphere_for_powermax_virtual_appliance
Published: May 22, 2026
Source: NVD
CVE-2022-31231 HIGH - 7.5

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.

Vendor: dell
Product: elastic_cloud_storage
Published: May 22, 2026
Source: NVD
CVE-2026-46670 CRITICAL - 9.8

YesWiki: Unauthenticated SQL Injection

Vendor: composer
Product: yeswiki/yeswiki
Published: May 22, 2026
Source: GitHub
CVE-2026-9256 HIGH - 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that re...

Published: May 22, 2026
Source: NVD
CVE-2026-8992 HIGH - 8.8

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

Vendor: ivanti
Product: secure_access_client
Published: May 22, 2026
Source: NVD
CVE-2026-8353 MEDIUM - 4.8

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious ...

Vendor: concretecms
Product: concrete_cms
Published: May 22, 2026
Source: NVD
CVE-2026-8347 MEDIUM - 4.3

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The...

Vendor: concretecms
Product: concrete_cms
Published: May 22, 2026
Source: NVD
CVE-2026-8340 MEDIUM - 4.3

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor's unpublished versi...

Vendor: concretecms
Product: concrete_cms
Published: May 22, 2026
Source: NVD
CVE-2025-46371 MEDIUM - 5.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2025-45145 HIGH - 7.5

Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter

Published: May 22, 2026
Source: NVD
CVE-2025-32751 MEDIUM - 5.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information.

Vendor: dell
Product: powerflex_appliance_intelligent_catalog
Published: May 22, 2026
Source: NVD
CVE-2021-21508 MEDIUM - 6.7

Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable applicat...

Published: May 22, 2026
Source: NVD
CVE-2026-9277 HIGH - 8.1

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.o...

Vendor: npm
Product: shell-quote
Published: May 22, 2026
Source: NVD

vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the hist...

Published: May 22, 2026
Source: NVD
CVE-2026-8673 MEDIUM - 5.9

Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD
CVE-2026-8672 MEDIUM - 5.1

Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0.

Published: May 22, 2026
Source: NVD