Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

760
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,061 - 1,080 of 27,228 CVEs
CVE-2021-47962 MEDIUM - 6.4

Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to inject malicious HTML and JavaScript code. Attackers can inject script payloads into user profile fields at the edit_user endpoint, which execute in the ...

Vendor: savsofts
Product: Savsoft Quiz
Published: May 15, 2026
Source: NVD
CVE-2021-47959 HIGH - 7.5

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads ...

Vendor: Wpgraphql
Product: WPGraphQL
Published: May 15, 2026
Source: NVD
CVE-2021-47958 MEDIUM - 4.3

CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services a...

Vendor: CouchCMS
Product: CouchCMS
Published: May 15, 2026
Source: NVD
CVE-2026-45619 MEDIUM - 6.5

AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45610 MEDIUM - 5.7

AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45580 MEDIUM - 5.4

AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45578 HIGH - 8.8

AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45575 HIGH - 7.4

Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client

Vendor: maven
Product: com.oviva.telematik:epa4all-client
Published: May 15, 2026
Source: GitHub
CVE-2026-45574 HIGH - 8.1

epa4all-client: TLS Certificate Validation Disabled in Production

Vendor: maven
Product: com.oviva.telematik:epa4all-client
Published: May 15, 2026
Source: GitHub
CVE-2026-46474 HIGH - 7.5

Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Vendor: TEODESIAN
Product: Trog::TOTP
Published: May 15, 2026
Source: NVD
CVE-2026-46491 HIGH - 8.6

SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion

Vendor: composer
Product: simplesamlphp/simplesamlphp-module-casserver
Published: May 15, 2026
Source: GitHub
CVE-2026-44692 HIGH - 7.7

Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint

Vendor: composer
Product: code16/sharp
Published: May 15, 2026
Source: GitHub
CVE-2026-45717 HIGH - 8.8

Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45715 HIGH - 7.7

Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45548 HIGH - 7.7

Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub
CVE-2026-45364 HIGH - 7.3

Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation

Vendor: npm
Product: better-auth
Published: May 15, 2026
Source: GitHub
CVE-2026-8695 HIGH - 7.5

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debu...

Vendor: radare
Product: radare2
Published: May 15, 2026
Source: NVD
CVE-2026-46383 MEDIUM - 5.5

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm instal...

Vendor: microsoft
Product: apm
Published: May 15, 2026
Source: NVD
CVE-2026-45539 HIGH - 7.4

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rglob() calls and read each match with Path.read_text(), transparently following symbolic links. A symli...

Vendor: microsoft
Product: apm
Published: May 15, 2026
Source: NVD
CVE-2026-45038 HIGH - 7.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD