Total CVEs

131,269

Critical Severity

2,778

High Severity

9,907

Last 7 Days

1,014
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 961 - 980 of 27,674 CVEs
CVE-2026-6367 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6366 MEDIUM - 6.6

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6365 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 1...

Vendor: drupal
Product: drupal
Published: May 19, 2026
Source: NVD
CVE-2026-6095 MEDIUM - 6.1

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS). This issue affects Orejime: from 0.0.0 before 2.0.16.

Vendor: gaya
Product: orejime
Published: May 19, 2026
Source: NVD
CVE-2026-34600 MEDIUM - 5.7

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully fixed by the prior pa...

Vendor: laurent22
Product: joplin
Published: May 19, 2026
Source: NVD
CVE-2026-5090 MEDIUM - 6.1

Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' t...

Published: May 19, 2026
Source: NVD
CVE-2026-34358 HIGH - 8.1

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on form display methods but omit equivalent checks on the corresponding write methods, allowing any auth...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2026-34246 MEDIUM - 4.8

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In app/Http/Controllers/Admin/RoleController.php, the datatable() method interpolates $role->name and ...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2026-34241 HIGH - 8.7

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitized reply content ($newmessage) is stored directly in database notification payloads and later rendered...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2026-34234 CRITICAL - 10.0

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler f...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2025-15645 MEDIUM - 4.6

Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-control...

Vendor: Ledger
Product: Ledger Nano X, Ledger Flex, Ledger Stax
Published: May 19, 2026
Source: NVD

Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potentially resulting in loss of confidentiality or integrity.

Published: May 19, 2026
Source: NVD
CVE-2023-7345 MEDIUM - 6.5

Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of characters. Attackers can obtai...

Published: May 19, 2026
Source: NVD
CVE-2026-39250 HIGH - 7.3

An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations.

Published: May 19, 2026
Source: NVD
CVE-2026-34233 MEDIUM - 6.5

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints without authorization checks, allowing any authenticated user to access sensitive administrative data that should be restricted to administrators only. ...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2026-34216 MEDIUM - 6.6

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied request input and used it for dynamic static method calls and object instantiation without any allowlist ...

Vendor: Ctrlpanel-gg
Product: panel
Published: May 19, 2026
Source: NVD
CVE-2026-32882 HIGH - 7.1

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color c...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-32814 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitializ...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-32741 HIGH - 7.1

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, d...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2025-57798 MEDIUM - 5.5

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial of Service (DoS) vulnerability in the title input functionality due to a lack of proper length validation. This flaw allows an attacker to cause an Out...

Vendor: laurent22
Product: joplin
Published: May 19, 2026
Source: NVD