Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,734
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,921 - 10,940 of 36,811 CVEs
CVE-2026-43903 HIGH - 7.8

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, sgiinput.cpp:265,274 use OIIO_DASSERT for bounds checking in the RLE decode loop. In release builds, OIIO_DASSERT compiles to ((void)sizeo...

Vendor: AcademySoftwareFoundation
Product: OpenImageIO
Published: May 14, 2026
Source: NVD

Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values

Published: May 14, 2026
Source: NVD
CVE-2026-45303 HIGH - 7.7

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, through the HTML rendering view, scripts can be injected and executed. The frontend provides a function to visualize the HTML content of a current chat. The content is embedded in an iF...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub
CVE-2026-45301 HIGH - 8.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform. This vulnerabi...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/Web...

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub
CVE-2026-45299 MEDIUM - 5.4

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, the profile_image_url field on the user profile update form accepted arbitrary data: URI values without MIME-type validation, resulting in a XSS vulnerability. This vulnerability is fix...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reach...

Vendor: go
Product: github.com/kumahq/kuma
Published: May 14, 2026
Source: GitHub
CVE-2026-8621 HIGH - 8.8

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a sha...

Published: May 14, 2026
Source: NVD
CVE-2026-44633 HIGH - 8.1

Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can cha...

Vendor: LiveHelperChat
Product: livehelperchat
Published: May 14, 2026
Source: NVD
CVE-2026-44592 CRITICAL - 9.4

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker without any credentials by sending a fresh, never-registered worker UUID. The resulting session has PeerA...

Vendor: wavelens
Product: gradient
Published: May 14, 2026
Source: NVD
CVE-2026-44586 HIGH - 8.3

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron wi...

Vendor: siyuan-note
Product: siyuan
Published: May 14, 2026
Source: NVD

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start th...

Vendor: midoks
Product: mdserver-web
Published: May 14, 2026
Source: NVD
CVE-2026-38740 MEDIUM - 5.3

Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Session Description Protocol (SDP), including ICE credentials and candidates, in cleartext over network interfaces. An attacker with network visibility can i...

Published: May 14, 2026
Source: NVD

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result,...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP
Published: May 14, 2026
Source: NVD

Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.

Vendor: pip
Product: ethyca-fides
Published: May 14, 2026
Source: GitHub
CVE-2026-45011 HIGH - 7.3

ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the Editor role can configure an image widget link to use a javascript: URL payload. Because editors have permission to pub...

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45013 HIGH - 8.1

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HTTP `Host` header when `apos.baseUrl` is not explicitly config...

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45012 HIGH - 7.6

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch att...

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-44990 CRITICAL - 9.3

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML o...

Vendor: npm
Product: sanitize-html
Published: May 14, 2026
Source: GitHub
CVE-2026-44973 HIGH - 8.1

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was ...

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 14, 2026
Source: GitHub