Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

788
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 961 - 980 of 27,228 CVEs
CVE-2026-8741 LOW - 3.1

A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH Packet Handler. Such manipulation leads to race condition. The attack may be performed from remote. A high complexity level is ...

Vendor: emqx
Product: emqx
Published: May 17, 2026
Source: NVD
CVE-2026-8740 MEDIUM - 6.3

A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes ...

Published: May 17, 2026
Source: NVD
CVE-2026-8739 MEDIUM - 5.3

A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptogr...

Published: May 17, 2026
Source: NVD
CVE-2026-8738 MEDIUM - 6.5

A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component...

Published: May 17, 2026
Source: NVD
CVE-2026-8737 MEDIUM - 5.3

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument ...

Published: May 17, 2026
Source: NVD
CVE-2026-8736 MEDIUM - 4.1

A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController. Performing a manipulation of the argument uniqueFileName results in path traversal. The attack may be carri...

Published: May 17, 2026
Source: NVD
CVE-2026-8735 MEDIUM - 6.3

A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit is publicly available ...

Published: May 17, 2026
Source: NVD
CVE-2026-8734 HIGH - 7.3

A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Interface. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed...

Published: May 17, 2026
Source: NVD
CVE-2026-8733 MEDIUM - 6.3

A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and c...

Published: May 17, 2026
Source: NVD
CVE-2026-8731 MEDIUM - 4.3

A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation of the argument client_pool leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disc...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8730 MEDIUM - 4.3

A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF. Executing a manipulation of the argument nfInstanceId can lead to denial of service. The attack may be performed from remote. The exploit has bee...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8729 MEDIUM - 4.3

A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/snssais results in denial of service. The attack is possible to be carried out remotely. The exploit i...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8728 MEDIUM - 4.3

A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. Such manipulation of the argument target-plmn-list leads to denial of service. The attack can be execu...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8719 HIGH - 8.8

The AI Engine โ€“ The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be...

Published: May 17, 2026
Source: NVD
CVE-2026-8725 HIGH - 7.3

A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been ...

Published: May 17, 2026
Source: NVD
CVE-2026-8724 MEDIUM - 4.7

A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been released to the public an...

Vendor: dataease
Product: dataease
Published: May 17, 2026
Source: NVD
CVE-2026-8723 MEDIUM - 5.3

### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). ### ...

Vendor: npm
Product: qs
Published: May 17, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: May 16, 2026
Source: NVD
CVE-2026-46728 HIGH - 8.2

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

Vendor: denx
Product: U-Boot
Published: May 16, 2026
Source: NVD
CVE-2021-47981 MEDIUM - 5.4

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arb...

Vendor: Opensolution
Product: Quick.CMS
Published: May 16, 2026
Source: NVD