Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,640
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,981 - 10,000 of 36,815 CVEs

Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BEAM atom table exhaustion. Multiple LiveView event handlers convert user-supplied event parameter strings to atoms using String.to_atom/1 without valid...

Vendor: erlang
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler in 'Elixir.PhoenixStorybook.Story.PlaygroundPreviewLive':handle_ev...

Vendor: erlang
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD

Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storybook/live/story/component_iframe...

Vendor: phenixdigital
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD
CVE-2026-24425 HIGH - 8.8

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fa...

Vendor: twigphp
Product: Twig
Published: May 20, 2026
Source: NVD
CVE-2026-22554 HIGH - 7.8

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 20, 2026
Source: NVD
CVE-2026-21836 MEDIUM - 6.5

The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query.  This could enable an authenticated attacker to view sensitive data.

Vendor: HCLSoftware
Product: DominoIQ
Published: May 20, 2026
Source: NVD
CVE-2026-5950 MEDIUM - 5.3

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through ...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-5947 HIGH - 7.5

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients" limit is reached (as would occur during...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-5946 HIGH - 7.5

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code pat...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-45584 HIGH - 8.1

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: malware_protection_engine
Published: May 20, 2026
Source: NVD
CVE-2026-45498 MEDIUM - 4.0

Microsoft Defender Denial of Service Vulnerability

Vendor: microsoft
Product: defender_antimalware_platform
Published: May 20, 2026
Source: NVD
CVE-2026-45443 MEDIUM - 5.0

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1.

Vendor: ADD-ONS.ORG
Product: PDF for Elementor Forms + Drag And Drop Template Builder
Published: May 20, 2026
Source: NVD
CVE-2026-42834 HIGH - 7.8

Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: windows_admin_center
Published: May 20, 2026
Source: NVD
CVE-2026-42383 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection. This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.29.0.

Vendor: YITH
Product: YITH WooCommerce Product Add-Ons
Published: May 20, 2026
Source: NVD
CVE-2026-41091 HIGH - 7.8

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: malware_protection_engine
Published: May 20, 2026
Source: NVD
CVE-2026-3593 HIGH - 7.4

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-3592 MEDIUM - 5.3

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 throu...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-3039 HIGH - 7.5

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-sec...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-29518 HIGH - 7.0

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can...

Vendor: RsyncProject
Product: rsync
Published: May 20, 2026
Source: NVD
CVE-2026-27424 MEDIUM - 4.3

Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.

Vendor: WP Chill
Product: Image Photo Gallery Final Tiles Grid
Published: May 20, 2026
Source: NVD