Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,669
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,121 - 10,140 of 36,814 CVEs
CVE-2026-46417 HIGH - 6.1

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server. The issue stems from how ...

Vendor: npm
Product: @angular/platform-server
Published: May 19, 2026
Source: GitHub
CVE-2026-46415 HIGH - 8.2

Caddy Defender trusted proxy client IP bypass

Vendor: go
Product: pkg.jsn.cam/caddy-defender
Published: May 19, 2026
Source: GitHub
CVE-2026-46412 CRITICAL - 10.0

Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) โ€” Mini Shai-Hulud worm

Vendor: npm
Product: @beproduct/nestjs-auth
Published: May 19, 2026
Source: GitHub
CVE-2026-42526 MEDIUM - 5.3

In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_team/conn"`) to the same path as another team's team-scoped secret when the caller had...

Vendor: Apache Software Foundation
Product: Apache Airflow Amazon provider
Published: May 19, 2026
Source: NVD
CVE-2026-32740 HIGH - 8.8

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-32739 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout a...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-27173 HIGH - 8.7

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Ai...

Vendor: Apache Software Foundation
Product: Apache Airflow CNCF Kubernetes provider
Published: May 19, 2026
Source: NVD

FileBrowser Quantum: unauthenticated user share share info

Vendor: go
Product: github.com/gtsteffaniak/filebrowser/backend
Published: May 19, 2026
Source: GitHub
CVE-2026-46374 HIGH - 7.5

SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to tri...

Vendor: pip
Product: sqlfluff
Published: May 19, 2026
Source: GitHub
CVE-2026-46373 HIGH - 7.5

SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.1.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any applic...

Vendor: pip
Product: sqlfluff
Published: May 19, 2026
Source: GitHub
CVE-2026-46372 HIGH - 8.5

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which accepts attacker-controlled baseUrl and uses it direc...

Vendor: npm
Product: sillytavern
Published: May 19, 2026
Source: GitHub
CVE-2026-46378 HIGH - 7.5

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

Vendor: go
Product: github.com/tomwright/dasel/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-46377 HIGH - 7.5

Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string

Vendor: go
Product: github.com/tomwright/dasel/v3
Published: May 19, 2026
Source: GitHub
CVE-2026-45783 HIGH - 7.5

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storage of any @libp2p/kad-dht node running in server mode by sending an unbounded stream of PUT_VALUE messages whose keys bypass all content validation. No ...

Vendor: npm
Product: @libp2p/kad-dht
Published: May 19, 2026
Source: GitHub
CVE-2026-46354 CRITICAL - 9.1

Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft

Vendor: go
Product: github.com/coder/coder/v2
Published: May 19, 2026
Source: GitHub

Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, the /__nuxt_island/* endpoint accepts attacker-controlled props query/body...

Vendor: npm
Product: nuxt
Published: May 19, 2026
Source: GitHub
CVE-2026-46338 MEDIUM - 4.3

Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path

Vendor: pip
Product: pymdown-extensions
Published: May 19, 2026
Source: GitHub
CVE-2026-45805 HIGH - 8.8

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint โ€” RCE

Vendor: npm
Product: @penpot/mcp
Published: May 19, 2026
Source: GitHub

FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2.6.7, an attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out....

Vendor: composer
Product: setasign/fpdi
Published: May 19, 2026
Source: GitHub
CVE-2026-45799 HIGH - 7.5

Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

Vendor: maven
Product: com.squareup.wire:wire-runtime-jvm
Published: May 19, 2026
Source: GitHub