Total CVEs

131,269

Critical Severity

2,778

High Severity

9,907

Last 7 Days

1,014
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,001 - 1,020 of 27,674 CVEs
CVE-2026-45796 MEDIUM - 6.5

Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint

Vendor: go
Product: github.com/coder/coder/v2
Published: May 19, 2026
Source: GitHub
CVE-2026-46357 MEDIUM - 6.5

HAX CMS: Denial of Service using Malicious Import Request

Vendor: npm
Product: @haxtheweb/haxcms-nodejs
Published: May 19, 2026
Source: GitHub
CVE-2026-45785 MEDIUM - 6.2

OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle

Vendor: nuget
Product: OpenMcdf
Published: May 19, 2026
Source: GitHub

rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers

Vendor: rust
Product: openssl
Published: May 19, 2026
Source: GitHub
CVE-2026-46339 CRITICAL - 10.0

9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

Vendor: npm
Product: 9router
Published: May 19, 2026
Source: GitHub
CVE-2026-45695 CRITICAL - 9.8

Kopia: RCE via SSH ProxyCommand Injection

Vendor: go
Product: github.com/kopia/kopia
Published: May 19, 2026
Source: GitHub

Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 allows Privilege Escalation, Target Programs with Elevated Privileges. This issue affects Automic Au...

Published: May 19, 2026
Source: NVD
CVE-2026-8096 MEDIUM - 6.5

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for auth...

Published: May 19, 2026
Source: NVD
CVE-2026-8073 HIGH - 7.5

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all versions up to, and including, 6.0.6. This makes it p...

Published: May 19, 2026
Source: NVD
CVE-2026-41470 MEDIUM - 5.9

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connectio...

Vendor: Live Networks, Inc.
Product: LIVE555
Published: May 19, 2026
Source: NVD

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completing payment. This issue has been fixed in versions ...

Vendor: discourse
Product: discourse
Published: May 19, 2026
Source: NVD
CVE-2026-33741 MEDIUM - 6.8

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline documents through both the attachment and image entry poin...

Vendor: espocrm
Product: espocrm
Published: May 19, 2026
Source: NVD
CVE-2026-33642 CRITICAL - 9.9

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/W...

Vendor: kovidgoyal
Product: kitty
Published: May 19, 2026
Source: NVD
CVE-2026-32738 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an e...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-8605 CRITICAL - 9.8

In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8604 HIGH - 8.8

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8603 CRITICAL - 9.8

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8602 CRITICAL - 9.1

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads toΒ Remote Code Execution (RCE), potentially allowing code execution on the affected system

Published: May 19, 2026
Source: NVD
CVE-2026-47107 CRITICAL - 9.6

Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certifica...

Vendor: windmill-labs
Product: windmill
Published: May 19, 2026
Source: NVD