Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 10,401 - 10,420 of 36,815 CVEs
CVE-2026-41568 MEDIUM - 6.1

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary ...

Vendor: go
Product: github.com/docker/docker
Published: May 18, 2026
Source: GitHub

CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve ...

Vendor: pip
Product: cloakbrowser
Published: May 18, 2026
Source: GitHub
CVE-2026-45358 MEDIUM - 5.3

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder. This issue has been patched in versions 6.9.13-47 and...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45359 MEDIUM - 5.7

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation. This issue has been patc...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45719 MEDIUM - 6.5

Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is interpolated directly into a CouchDB reduce function definition without validation. Although an internal SCHEMA_MAP object defines the valid...

Vendor: npm
Product: @budibase/server
Published: May 18, 2026
Source: GitHub
CVE-2026-41567 HIGH - 7.2

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `un...

Vendor: go
Product: github.com/moby/moby/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45718 MEDIUM - 5.4

Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:sourceId/actions/:actionId/trigger) fails to validate that the user-supplied rowId is within the scope of the view's row filters. A user with access to a filtered view can trigger r...

Vendor: npm
Product: budibase
Published: May 18, 2026
Source: GitHub
CVE-2026-45716 HIGH - 8.8

Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), ...

Vendor: npm
Product: @budibase/worker
Published: May 18, 2026
Source: GitHub
CVE-2026-45707 HIGH - 8.1

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the target n8n instance is selected per-request from x-n8n-url / x-n8n-key headers. Requests that omitt...

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in versions 2.6.23 and 3.0.6.

Vendor: composer
Product: sulu/sulu
Published: May 18, 2026
Source: GitHub
CVE-2026-45363 HIGH - 7.4

ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351

Vendor: rubygems
Product: jwt
Published: May 18, 2026
Source: GitHub
CVE-2026-45697 CRITICAL - 9.8

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value β†’ Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending ...

Vendor: composer
Product: verbb/formie
Published: May 18, 2026
Source: GitHub
CVE-2026-45327 HIGH - 8.2

TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the issue by requiring either HTTP Basic auth or a `?password=` query parameter, comparing the supplied p...

Vendor: go
Product: github.com/DatanoiseTV/tinyice
Published: May 18, 2026
Source: GitHub
CVE-2026-8843 MEDIUM - 6.5

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "queryable_encrypted_range" indices. This issue a...

Published: May 18, 2026
Source: NVD

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in theΒ /api/v2/tenants/{tenant}/databases/{db}/...

Vendor: Chroma
Product: ChromaDB
Published: May 18, 2026
Source: NVD
CVE-2026-41085 HIGH - 8.8

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces.

Published: May 18, 2026
Source: NVD
CVE-2026-38719 MEDIUM - 6.2

OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF message can supply an attacker-controlled item_count value that is not consistently v...

Published: May 18, 2026
Source: NVD
CVE-2026-45325 HIGH - 8.2

@tmlmobilidade/utils has prototype pollution in its setValueAtPath

Vendor: npm
Product: @tmlmobilidade/utils
Published: May 18, 2026
Source: GitHub
CVE-2026-45302 HIGH - 8.2

parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with ...

Vendor: npm
Product: parse-nested-form-data
Published: May 18, 2026
Source: GitHub
CVE-2026-45300 HIGH - 7.4

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a d...

Vendor: maven
Product: org.asynchttpclient:async-http-client
Published: May 18, 2026
Source: GitHub