Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,514
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,381 - 10,400 of 36,815 CVEs
CVE-2026-45242 HIGH - 7.1

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slidesDir request parameter. Attackers can exploit thi...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-45231 MEDIUM - 6.1

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side sanitization and rendered using innerHTML without client-side escaping. Attackers can create or update a...

Vendor: DumbWareio
Product: DumbAssets
Published: May 18, 2026
Source: NVD
CVE-2026-45731 MEDIUM - 4.9

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to r...

Vendor: composer
Product: WWBN/AVideo
Published: May 18, 2026
Source: GitHub
CVE-2026-45495 HIGH - 8.8

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Vendor: microsoft
Product: edge_chromium
Published: May 18, 2026
Source: NVD
CVE-2026-45494 MEDIUM - 5.4

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Vendor: microsoft
Product: edge_chromium
Published: May 18, 2026
Source: NVD
CVE-2026-45492 MEDIUM - 5.4

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 18, 2026
Source: NVD
CVE-2026-45230 CRITICAL - 9.1

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the o...

Vendor: DumbWareio
Product: DumbAssets
Published: May 18, 2026
Source: NVD
CVE-2026-42822 CRITICAL - 10.0

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_local
Published: May 18, 2026
Source: NVD
CVE-2026-32849 MEDIUM - 5.5

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_l...

Vendor: NetBSD
Product: src
Published: May 18, 2026
Source: NVD
CVE-2026-32848 MEDIUM - 4.7

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mu...

Vendor: NetBSD
Product: src
Published: May 18, 2026
Source: NVD
CVE-2026-29965 MEDIUM - 6.1

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscated JavaScript syntax.

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-29964 MEDIUM - 6.1

HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript syntax. The endpoint reflects unsanitized user input in HTTP responses without adequate output ...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-29963 HIGH - 7.5

HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this fl...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2026-29962 HIGH - 7.5

HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, ...

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD
CVE-2023-24215 CRITICAL - 9.1

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.

Published: May 18, 2026
Source: NVD
CVE-2026-45678 HIGH - 7.5

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the e...

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45679 MEDIUM - 6.5

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tok...

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45676 MEDIUM - 5.5

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF parser trusts section offsets, counts, and string offsets from the executable file. A crafted local ELF can make OBI dereference invalid section po...

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45031 MEDIUM - 5.3

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would sti...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-42306 HIGH - 7.2

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary ho...

Vendor: go
Product: github.com/docker/docker
Published: May 18, 2026
Source: GitHub