Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,740
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,941 - 9,960 of 36,811 CVEs
CVE-2026-24188 HIGH - 8.2

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.

Vendor: NVIDIA
Product: TensorRT
Published: May 20, 2026
Source: NVD

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnera...

Vendor: xwiki
Product: xwiki-commons
Published: May 20, 2026
Source: NVD
CVE-2026-30691 MEDIUM - 6.1

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode

Published: May 20, 2026
Source: NVD
CVE-2026-20240 MEDIUM - 6.5

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the โ€˜adminโ€™ or โ€˜powerโ€™ Splunk roles could cause a Denial of ...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-20239 HIGH - 7.5

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-20238 MEDIUM - 6.5

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configu...

Vendor: Splunk
Product: Splunk AI Toolkit
Published: May 20, 2026
Source: NVD
CVE-2026-9101 MEDIUM - 4.3

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

Published: May 20, 2026
Source: NVD
CVE-2026-9100 MEDIUM - 5.9

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process ...

Published: May 20, 2026
Source: NVD
CVE-2026-9087 MEDIUM - 6.4

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Published: May 20, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 20, 2026
Source: NVD
CVE-2026-7613 HIGH - 7.2

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

Published: May 20, 2026
Source: NVD
CVE-2026-44926 HIGH - 8.8

InfoScale CmdServer before 7.4.2 mishandles access control.

Published: May 20, 2026
Source: NVD
CVE-2026-44925 HIGH - 8.8

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-44924 MEDIUM - 5.4

InfoScale VIOM 9.1.3 allows XSS.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-44923 MEDIUM - 6.5

SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-20223 CRITICAL - 10.0

A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role. This vulnerability is due to insufficient validation and authentication wh...

Vendor: Cisco
Product: Cisco Secure Workload
Published: May 20, 2026
Source: NVD
CVE-2026-20206 MEDIUM - 6.3

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEy...

Vendor: Cisco
Product: Cisco ThousandEyes Enterprise Agent
Published: May 20, 2026
Source: NVD
CVE-2026-20199 MEDIUM - 4.7

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authentica...

Vendor: Cisco
Product: Cisco ThousandEyes Enterprise Agent
Published: May 20, 2026
Source: NVD
CVE-2026-20171 MEDIUM - 6.8

A vulnerability in the Border Gateway Protocol (BGP)&nbsp;enforce-first-as feature of&nbsp;Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of servic...

Vendor: Cisco
Product: Cisco NX-OS Software
Published: May 20, 2026
Source: NVD

MISPโ€™s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an attacker with a valid OI...

Published: May 20, 2026
Source: NVD