Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,421 - 10,440 of 36,815 CVEs
CVE-2026-45298 HIGH - 8.6

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that ...

Vendor: go
Product: github.com/amir20/dozzle
Published: May 18, 2026
Source: GitHub
CVE-2026-46385 HIGH - 7.5

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd6...

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45270 HIGH - 8.7

CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-46384 HIGH - 7.5

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before bounds-checking, or summed them with overflow-prone signed-int arithmetic. On 32-bit targets (GOARCH=...

Vendor: go
Product: github.com/iskorotkov/avro/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45149 MEDIUM - 6.5

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate ele...

Vendor: npm
Product: brace-expansion
Published: May 18, 2026
Source: GitHub
CVE-2026-45139 MEDIUM - 6.5

CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-36438 MEDIUM - 5.3

An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd

Published: May 18, 2026
Source: NVD
CVE-2026-20685 MEDIUM - 6.5

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

Vendor: Apple
Product: Private Cloud Compute Server Software
Published: May 18, 2026
Source: NVD
CVE-2025-57282 HIGH - 8.8

ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.

Published: May 18, 2026
Source: NVD
CVE-2025-56352 HIGH - 7.5

In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length Client ID while CleanSession is set to 0, the broker correctly replies with a CONNACK return code 0x02...

Published: May 18, 2026
Source: NVD
CVE-2026-45138 MEDIUM - 5.4

CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: May 18, 2026
Source: GitHub
CVE-2026-45660 MEDIUM - 5.4

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the server to make ...

Vendor: composer
Product: statamic/cms
Published: May 18, 2026
Source: GitHub
CVE-2026-42326 MEDIUM - 5.1

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte. This issue has been patched in versions 6.9.13-47 and 7...

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-41949 MEDIUM - 5.9

Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-41948 HIGH - 7.7

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unenc...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-41947 HIGH - 7.4

Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to...

Vendor: langgenius
Product: dify
Published: May 18, 2026
Source: NVD
CVE-2026-39079 HIGH - 7.5

An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components

Published: May 18, 2026
Source: NVD
CVE-2026-26462 HIGH - 7.3

Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary o...

Published: May 18, 2026
Source: NVD

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request target is passed as a URI object (rather than a String) to Faraday::Connection#build_exclusive_url. This...

Vendor: rubygems
Product: faraday
Published: May 18, 2026
Source: GitHub

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve u...

Vendor: npm
Product: neotoma
Published: May 18, 2026
Source: GitHub