Total CVEs

138,170

Critical Severity

3,538

High Severity

12,685

Last 7 Days

1,964
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,021 - 1,040 of 3,412 CVEs
CVE-2025-6577 CRITICAL - 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection. This issue affects E-Commerce Website: before 4.5.001.

Published: May 12, 2026
Source: NVD
CVE-2025-40949 CRITICAL - 9.1

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM...

Vendor: Siemens
Product: RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1510, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, RUGGEDCOM ROX RX5000
Published: May 12, 2026
Source: NVD
CVE-2026-34263 CRITICAL - 9.6

Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.

Vendor: SAP_SE
Product: SAP Commerce cloud configuration
Published: May 12, 2026
Source: NVD
CVE-2026-34260 CRITICAL - 9.6

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The application directly concatenates this malicious user input into SQL queries, which are then passed to the u...

Vendor: SAP_SE
Product: SAP S/4HANA (SAP Enterprise Search for ABAP)
Published: May 12, 2026
Source: NVD
CVE-2026-45393 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Edge
Published: May 12, 2026
Source: NVD
CVE-2026-45392 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Stream
Published: May 12, 2026
Source: NVD
CVE-2026-45391 CRITICAL - 9.8

Reserved. Details will be published at disclosure.

Vendor: Cribl
Product: Cribl Edge
Published: May 12, 2026
Source: NVD
CVE-2026-45321 CRITICAL - 9.6

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself wa...

Vendor: npm
Product: @tanstack/arktype-adapter
Published: May 12, 2026
Source: NVD
CVE-2026-43900 CRITICAL - 9.3

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. The SVGSanitizer (s...

Vendor: ThinkInAIXYZ
Product: deepchat
Published: May 11, 2026
Source: NVD
CVE-2026-43899 CRITICAL - 9.6

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE). While the patch correctly restricted api.openExter...

Vendor: ThinkInAIXYZ
Product: deepchat
Published: May 11, 2026
Source: NVD
CVE-2026-42869 CRITICAL - 10.0

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET...

Vendor: socfortress
Product: CoPilot
Published: May 11, 2026
Source: NVD
CVE-2026-43898 CRITICAL - 10.0

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked ho...

Vendor: npm
Product: @nyariv/sandboxjs
Published: May 11, 2026
Source: GitHub
CVE-2026-7210 CRITICAL - 9.8

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Vendor: libexpat_project
Product: libexpat
Published: May 11, 2026
Source: NVD
CVE-2026-38567 CRITICAL - 9.8

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker can bypass authentication by supplying a crafted username (e.g. admin'--) or extract the full con...

Published: May 11, 2026
Source: NVD
CVE-2026-25244 CRITICAL - 9.8

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metachara...

Vendor: npm
Product: @wdio/browserstack-service
Published: May 11, 2026
Source: GitHub
CVE-2026-7813 CRITICAL - 9.9

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-owned objects without filtering by the requesting user's identity. An authenticated user could access another user&...

Published: May 11, 2026
Source: NVD
CVE-2026-44643 CRITICAL - 10.0

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.

Vendor: peerigon
Product: angular-expressions
Published: May 11, 2026
Source: NVD
CVE-2026-44477 CRITICAL - 9.9

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session with SET ROLE pg_monito...

Vendor: go
Product: github.com/cloudnative-pg/cloudnative-pg
Published: May 11, 2026
Source: GitHub
CVE-2026-40636 CRITICAL - 9.8

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0,ย contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.

Vendor: Dell
Product: ECS, ObjectScale
Published: May 11, 2026
Source: NVD
CVE-2021-47940 CRITICAL - 9.8

WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_fr...

Vendor: download-from-files
Product: Download From Files
Published: May 10, 2026
Source: NVD