Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,921 - 9,940 of 36,815 CVEs
CVE-2026-9082 MEDIUM - 6.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from...

Vendor: drupal
Product: drupal
Published: May 20, 2026
Source: NVD
CVE-2026-47099 MEDIUM - 6.1

TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted JSON payload containing a malicious _constructor-name_ property value. The custom reviver passes the constructor name ...

Vendor: storybookjs
Product: telejson
Published: May 20, 2026
Source: NVD
CVE-2026-45444 CRITICAL - 10.0

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

Vendor: WP Swings
Product: Gift Cards For WooCommerce Pro
Published: May 20, 2026
Source: NVD

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.

Vendor: frappe
Product: lms
Published: May 20, 2026
Source: NVD

Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue is resolved in versions 16.15.0, 15.105.0 and above.

Vendor: frappe
Product: frappe
Published: May 20, 2026
Source: NVD
CVE-2026-39311 MEDIUM - 6.8

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw where lack of SVG sanitization combined with a disabled Content Security Policy (CSP) and a publicly reachable backe...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-39310 HIGH - 8.6

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an ...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-35016 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_query POST parameter directly into an HTML input field VALUE attribute. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35015 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the the_ticket GET parameter directly into a JavaScript variable assignment. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35014 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attacker...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35013 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values through the thelat and thelng GET parameters directly into JavaScript variable assignments. Atta...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35012 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attack...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35011 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_call GET parameter directly into page output. Attackers can craft a malicious URL co...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35010 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a JavaScript variable assignment. Attackers c...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35009 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35008 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into an HTML attribute. Attackers can craft a maliciou...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD
CVE-2026-35007 MEDIUM - 4.6

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id GET parameter directly into an HTML attribute. Attackers can craft a malicious ...

Vendor: openises
Product: tickets
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without ...

Vendor: xwiki
Product: xwiki-platform
Published: May 20, 2026
Source: NVD
CVE-2026-2813 MEDIUM - 4.7

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended, untrusted site, resulting ...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD
CVE-2026-2812 MEDIUM - 5.3

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This is...

Vendor: esri
Product: arcgis_server
Published: May 20, 2026
Source: NVD