Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,881 - 10,900 of 36,761 CVEs
CVE-2026-44586 HIGH - 8.3

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron wi...

Vendor: siyuan-note
Product: siyuan
Published: May 14, 2026
Source: NVD

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start th...

Vendor: midoks
Product: mdserver-web
Published: May 14, 2026
Source: NVD
CVE-2026-38740 MEDIUM - 5.3

Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Session Description Protocol (SDP), including ICE credentials and candidates, in cleartext over network interfaces. An attacker with network visibility can i...

Published: May 14, 2026
Source: NVD

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result,...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP
Published: May 14, 2026
Source: NVD

Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.

Vendor: pip
Product: ethyca-fides
Published: May 14, 2026
Source: GitHub
CVE-2026-45011 HIGH - 7.3

ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the Editor role can configure an image widget link to use a javascript: URL payload. Because editors have permission to pub...

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45013 HIGH - 8.1

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HTTP `Host` header when `apos.baseUrl` is not explicitly config...

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45012 HIGH - 7.6

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch att...

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-44990 CRITICAL - 9.3

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML o...

Vendor: npm
Product: sanitize-html
Published: May 14, 2026
Source: GitHub
CVE-2026-44973 HIGH - 8.1

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was ...

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 14, 2026
Source: GitHub

dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub
CVE-2026-44968 MEDIUM - 6.3

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.

Published: May 14, 2026
Source: NVD
CVE-2026-46470 MEDIUM - 4.0

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

Vendor: GStreamer
Product: Good Plug-ins
Published: May 14, 2026
Source: NVD
CVE-2026-46469 MEDIUM - 4.0

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

Vendor: GStreamer
Product: Good Plug-ins
Published: May 14, 2026
Source: NVD
CVE-2026-42897 HIGH - 8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: exchange_server
Published: May 14, 2026
Source: NVD

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible to request paths such as http://localhost:8080/c:/Windows/System32/drivers/etc/hosts and have the cont...

Vendor: Badgerati
Product: Pode
Published: May 14, 2026
Source: NVD
CVE-2026-41615 CRITICAL - 9.6

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: authenticator
Published: May 14, 2026
Source: NVD
CVE-2025-15024 HIGH - 8.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Remote Code Inclusion. This issue affects Library Automation System: from v.19.5 be...

Vendor: Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.
Product: Library Automation System
Published: May 14, 2026
Source: NVD