Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,875
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 941 - 960 of 3,396 CVEs
CVE-2026-40621 CRITICAL - 9.8

ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.

Vendor: ELECOM CO.,LTD.
Product: WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, WRC-W702-B
Published: May 13, 2026
Source: NVD
CVE-2026-32661 CRITICAL - 9.8

Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpassw...

Vendor: Canon Marketing Japan Inc.
Product: GUARDIANWALL MailSuite (On-premises version), GUARDIANWALL Mail Security Cloud (SaaS version)
Published: May 13, 2026
Source: NVD
CVE-2025-11159 CRITICAL - 9.1

Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by aΒ data source administrator.

Vendor: Hitachi Vantara
Product: Pentaho Data Integration and Analytics
Published: May 13, 2026
Source: NVD

mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33...

Vendor: maven
Product: org.mapfish.print:print-lib
Published: May 13, 2026
Source: GitHub
CVE-2026-44547 CRITICAL - 9.6

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/public/public-user.php by an unrelated PR before any 7.2.x tag was cut. Every shipped 7.2.x release there...

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD
CVE-2026-42288 CRITICAL - 10.0

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard via unsanitized DB_PASSWORD remains fully exploitable This vulnerability is fixed in 7.3.2.

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD
CVE-2026-44650 CRITICAL - 9.1

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts extensionName: "." which bypasses sanitize-fi...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub
CVE-2026-44649 CRITICAL - 9.8

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to auto...

Vendor: npm
Product: sillytavern
Published: May 12, 2026
Source: GitHub

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ultimately writes the data to storage via buildStorage.Put. The router concatenates the path components w...

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: May 12, 2026
Source: GitHub
CVE-2026-42854 CRITICAL - 9.8

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP heade...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-45185 CRITICAL - 9.8

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to hea...

Vendor: Exim
Product: Exim
Published: May 12, 2026
Source: NVD
CVE-2026-44225 CRITICAL - 9.3

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A validateFsPath() function is supposed to sandbox this access, but its blocklist is...

Vendor: enesgkky
Product: Pulpy
Published: May 12, 2026
Source: NVD
CVE-2026-42889 CRITICAL - 9.1

Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connections without a token query parameter were incorrectly treated as having full serve...

Vendor: No-Instructions
Product: relay-server
Published: May 12, 2026
Source: NVD
CVE-2026-34660 CRITICAL - 9.3

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially ga...

Vendor: Adobe
Product: Adobe Connect
Published: May 12, 2026
Source: NVD
CVE-2026-34659 CRITICAL - 9.6

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this is...

Vendor: Adobe
Product: Adobe Connect
Published: May 12, 2026
Source: NVD
CVE-2026-44343 CRITICAL - 9.8

WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. This vulnerability is fixed in 4.3.2.

Vendor: WGDashboard
Product: WGDashboard
Published: May 12, 2026
Source: NVD
CVE-2026-44277 CRITICAL - 9.8

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Vendor: Fortinet
Product: FortiAuthenticator
Published: May 12, 2026
Source: NVD
CVE-2026-44196 CRITICAL - 9.1

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker ...

Vendor: smp46
Product: pingvin-share-x
Published: May 12, 2026
Source: NVD
CVE-2026-44183 CRITICAL - 9.8

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the client IP. That entry ...

Vendor: Cleanuparr
Product: Cleanuparr
Published: May 12, 2026
Source: NVD
CVE-2026-42898 CRITICAL - 9.9

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: dynamics_365
Published: May 12, 2026
Source: NVD