Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,441 - 10,460 of 36,815 CVEs
CVE-2026-45627 HIGH - 8.2

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45626 MEDIUM - 6.3

Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell command (sh -c "find โ€ฆ | while โ€ฆ") inside an Arcane helper container. The...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45625 CRITICAL - 9.9

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials. E...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 18, 2026
Source: GitHub
CVE-2026-45135 HIGH - 8.1

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct...

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: May 18, 2026
Source: GitHub
CVE-2026-45620 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenticated user enumeration.

Vendor: composer
Product: WWBN/AVideo
Published: May 18, 2026
Source: GitHub
CVE-2026-45609 HIGH - 7.2

mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted UR...

Vendor: maven
Product: org.springaicommunity:mcp-client-security
Published: May 18, 2026
Source: GitHub
CVE-2026-46510 HIGH - 8.2

form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose name starts with __proto__[...] causes the library to mu...

Vendor: npm
Product: form-data-objectizer
Published: May 18, 2026
Source: GitHub
CVE-2026-45582 MEDIUM - 6.5

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry bac...

Vendor: npm
Product: n8n-mcp
Published: May 18, 2026
Source: GitHub
CVE-2026-42009 HIGH - 7.5

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This cou...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: May 18, 2026
Source: NVD
CVE-2026-8803 LOW - 3.7

A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have...

Published: May 18, 2026
Source: NVD
CVE-2026-7304 CRITICAL - 9.8

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD
CVE-2026-7302 CRITICAL - 9.1

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD
CVE-2026-7301 CRITICAL - 9.8

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.

Vendor: lmsys
Product: sglang
Published: May 18, 2026
Source: NVD

Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash

Published: May 18, 2026
Source: NVD
CVE-2026-8802 MEDIUM - 4.3

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identifie...

Published: May 18, 2026
Source: NVD

Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running and enabling privilege escalation without the need for ...

Published: May 18, 2026
Source: NVD
CVE-2026-41119 MEDIUM - 6.8

Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.

Vendor: Dell
Product: Live Optics
Published: May 18, 2026
Source: NVD
CVE-2026-7498 HIGH - 8.8

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. This issue affects DernekWeb: through 30122025.

Published: May 18, 2026
Source: NVD

A vulnerability in Command-Line Client in P4 Server prior to the 2025.2 Patch 2, identified as CVE-2026-6902, has been fixed in P4 Server to address potential security risks.

Published: May 18, 2026
Source: NVD
CVE-2026-6347 HIGH - 7.6

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the expor...

Vendor: mattermost
Product: mattermost_server
Published: May 18, 2026
Source: NVD