Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,641 - 9,660 of 36,689 CVEs
CVE-2026-48226 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ref and mode_orig POST parameters directly into HTML form hidden input value attribut...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48225 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the _type POST parameter directly into an HTML form hidden input value attribute. Attackers ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48224 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. Att...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48223 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. A...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48222 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. Att...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48221 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. At...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48220 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. Att...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48219 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_add_str POST parameter directly into an HTML form hidden input value attribute. Att...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48218 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_name and frm_id POST parameters directly into rendered HTML content an...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48217 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the multiple POST parameters (module_choice, flag, confirmation) directly into rende...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48216 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the multiple POST parameters (ticketshost, ticketsdb, ticketsuser, ticketspassword, tick...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48215 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_id POST parameter directly into an HTML form input value attribute. Attackers can c...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48214 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id POST parameter directly into an HTML form input value attribute and an inline...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-39593 MEDIUM - 6.5

Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HAPPY: from n/a through 1.0.10.

Vendor: VillaTheme
Product: HAPPY
Published: May 21, 2026
Source: NVD
CVE-2026-46492 HIGH - 7.2

md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is process...

Vendor: npm
Product: md-fileserver
Published: May 21, 2026
Source: GitHub
CVE-2026-46432 HIGH - 7.8

LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call sites. At time of publication, there a...

Vendor: pip
Product: lmdeploy
Published: May 21, 2026
Source: GitHub
CVE-2026-48213 MEDIUM - 5.4

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id POST parameter directly into an HTML form input value attribute. Attackers can c...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48207 CRITICAL - 9.8

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Pyt...

Vendor: Apache Software Foundation
Product: Apache Fory
Published: May 21, 2026
Source: NVD
CVE-2026-46490 HIGH - 8.8

samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an attribute value (e.g., em...

Vendor: npm
Product: samlify
Published: May 21, 2026
Source: GitHub

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise. Prior to version 2026.5.12, there is a path traversal vulnerability via unsanitized File identifiers in iOS Backup processing. This issue has been patched in version ...

Vendor: pip
Product: mvt
Published: May 21, 2026
Source: GitHub