Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,641 - 9,660 of 36,778 CVEs
CVE-2026-22678 MEDIUM - 5.4

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized...

Vendor: Webmin
Product: Webmin
Published: May 21, 2026
Source: NVD
CVE-2026-46703 CRITICAL - 9.6

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in ...

Vendor: pip
Product: boxlite
Published: May 21, 2026
Source: GitHub
CVE-2026-46695 CRITICAL - 10.0

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the director...

Vendor: pip
Product: boxlite
Published: May 21, 2026
Source: GitHub

@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty

Vendor: npm
Product: @nevware21/ts-utils
Published: May 21, 2026
Source: GitHub

containerd user ID handling bypass allows runAsNonRoot evasion

Vendor: go
Product: github.com/containerd/containerd
Published: May 21, 2026
Source: GitHub
CVE-2026-46679 HIGH - 7.5

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23.

Vendor: npm
Product: @libp2p/gossipsub
Published: May 21, 2026
Source: GitHub
CVE-2026-46678 MEDIUM - 6.8

Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)

Vendor: pip
Product: pydantic-ai
Published: May 21, 2026
Source: GitHub
CVE-2026-46671 MEDIUM - 4.4

Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory

Vendor: rust
Product: onenote_parser
Published: May 21, 2026
Source: GitHub
CVE-2026-46645 MEDIUM - 4.3

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endpoints enforce. If a developer restricts model access by overriding is_accessible(), an authenticated ...

Vendor: pip
Product: sqladmin
Published: May 21, 2026
Source: GitHub

Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: Sandbox property and method bypass via object-destructuring assignment

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

Vendor: composer
Product: twig/markdown-extra
Published: May 21, 2026
Source: GitHub

Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: PHP code injection via `{% use %}` template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments

Vendor: composer
Product: twig/intl-extra
Published: May 21, 2026
Source: GitHub

Twig: The `spaceless` filter implicitly marks its output as safe

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub
CVE-2026-46625 HIGH - 7.5

JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an o...

Vendor: npm
Product: js-cookie
Published: May 21, 2026
Source: GitHub
CVE-2026-8428 HIGH - 8.8

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->token->validate('do_update&#...

Vendor: concretecms
Product: concrete_cms
Published: May 21, 2026
Source: NVD