Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,956
Quick preset (or use dates below)
Clear Filters
Showing 1,001 - 1,020 of 3,545 CVEs
CVE-2026-31230 CRITICAL - 9.8

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the unsafe eval() function to parse string values provided via the --clip_values and --input_shape command-...

Published: May 12, 2026
Source: NVD
CVE-2026-31229 CRITICAL - 9.8

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., model.pt) during robustness evaluation, the code uses torch.load() without the...

Published: May 12, 2026
Source: NVD
CVE-2026-29204 CRITICAL - 10.0

Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's resources and their cPanel account.

Vendor: WebPros
Product: WHMCS
Published: May 12, 2026
Source: NVD
CVE-2026-26083 CRITICAL - 9.8

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all vers...

Vendor: Fortinet
Product: FortiSandbox Cloud, FortiSandbox, FortiSandbox PaaS
Published: May 12, 2026
Source: NVD
CVE-2026-43992 CRITICAL - 9.8

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accepted 'mnemonic: string' as an explicit tool-call parameter. The BIP-39 seed was consequently ...

Vendor: Dragonmonk111
Product: junoclaw
Published: May 12, 2026
Source: NVD
CVE-2025-65719 CRITICAL - 9.8

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

Published: May 12, 2026
Source: NVD
CVE-2026-42074 CRITICAL - 9.8

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can ...

Vendor: npm
Product: openclaude
Published: May 12, 2026
Source: GitHub
CVE-2026-43515 CRITICAL - 9.1

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0....

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: May 12, 2026
Source: NVD
CVE-2026-43512 CRITICAL - 9.8

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported version...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: May 12, 2026
Source: NVD
CVE-2026-41293 CRITICAL - 9.8

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to u...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: May 12, 2026
Source: NVD
CVE-2026-34187 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800

Vendor: Pandora FMS
Product: Pandora FMS
Published: May 12, 2026
Source: NVD
CVE-2026-31228 CRITICAL - 9.8

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe eval() function to dynamically evaluate user-supplied strings for the LossFn and Optimizer parameters w...

Published: May 12, 2026
Source: NVD
CVE-2026-31226 CRITICAL - 9.8

The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerability arises from the unsafe construction and execution of shell commands via os.system() without prop...

Published: May 12, 2026
Source: NVD
CVE-2026-31220 CRITICAL - 9.8

PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system allows low-privileged users to submit Python functions (via @sy.syft_function()) for remote execution on the server. While...

Published: May 12, 2026
Source: NVD
CVE-2026-31217 CRITICAL - 9.8

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user supplies a directory path via the --model command-line argument, the function reads a module.py file ...

Published: May 12, 2026
Source: NVD
CVE-2026-31216 CRITICAL - 9.1

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentication, authorization, and input validation mechanisms. Unauthenticated remote attackers can send craft...

Published: May 12, 2026
Source: NVD
CVE-2026-31215 CRITICAL - 9.1

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper authentication and authorization controls and does not validate the user-supplied path_or_url parameter....

Published: May 12, 2026
Source: NVD
CVE-2026-31214 CRITICAL - 9.8

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load() to process PyTorch checkpoint files (.pt) without enabling the security-restr...

Published: May 12, 2026
Source: NVD
CVE-2026-30805 CRITICAL - 9.1

Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800

Vendor: Pandora FMS
Product: Pandora FMS
Published: May 12, 2026
Source: NVD
CVE-2026-8401 CRITICAL - 9.8

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

Vendor: mozilla
Product: firefox
Published: May 12, 2026
Source: NVD