Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

759
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,081 - 1,100 of 27,228 CVEs
CVE-2026-45037 HIGH - 7.1

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafte...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45036 HIGH - 7.0

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatically confirms ZMODEM protocol detection on all terminal session output without user interaction, enabling shell command execution when a user displays attacker-controlled content. Th...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-45035 HIGH - 8.8

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or san...

Vendor: Eugeny
Product: tabby
Published: May 15, 2026
Source: NVD
CVE-2026-44717 CRITICAL - 9.8

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.

Vendor: 611711Dark
Product: mcp_calculate_server
Published: May 15, 2026
Source: NVD

LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key for an HS256/HS384/HS512 token. In the OpenSSL backend, this causes HMAC verification to run with a zero-length key, so an attacker can forge a valid JW...

Vendor: benmcollins
Product: libjwt
Published: May 15, 2026
Source: NVD
CVE-2026-23695 MEDIUM - 5.4

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html direct...

Vendor: Cockpit-HQ
Product: Cockpit
Published: May 15, 2026
Source: NVD
CVE-2026-45106 MEDIUM - 4.6

Weblate: Stored HTML injection in editor search preview

Vendor: pip
Product: weblate
Published: May 15, 2026
Source: GitHub
CVE-2026-45062 HIGH - 8.1

FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files

Vendor: go
Product: github.com/dunglas/frankenphp
Published: May 15, 2026
Source: GitHub
CVE-2026-44716 HIGH - 7.5

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

Vendor: pip
Product: pipecat-ai
Published: May 15, 2026
Source: GitHub
CVE-2026-41147 HIGH - 8.7

NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class

Vendor: composer
Product: nukeviet/nukeviet
Published: May 15, 2026
Source: GitHub
CVE-2026-40092 HIGH - 7.5

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, Ke...

Vendor: rust
Product: nimiq-keys
Published: May 15, 2026
Source: GitHub
CVE-2026-22810 HIGH - 8.2

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded fil...

Vendor: npm
Product: @joplin/onenote-converter
Published: May 15, 2026
Source: GitHub
CVE-2025-65954 MEDIUM - 4.7

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the br...

Vendor: composer
Product: simplesamlphp/simplesamlphp-module-casserver
Published: May 15, 2026
Source: GitHub
CVE-2026-46508 HIGH - 7.8

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and tas...

Vendor: vercel
Product: turborepo
Published: May 15, 2026
Source: NVD

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed. The vulnerability...

Vendor: cli
Product: cli
Published: May 15, 2026
Source: NVD
CVE-2026-45773 MEDIUM - 6.5

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send...

Vendor: vercel
Product: turborepo
Published: May 15, 2026
Source: NVD
CVE-2026-45772 CRITICAL - 9.8

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package manager detection exe...

Vendor: vercel, @turbo
Product: turborepo, codemod, workspaces
Published: May 15, 2026
Source: NVD
CVE-2026-35194 HIGH - 8.1

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE exp...

Vendor: Apache Software Foundation
Product: Apache Flink
Published: May 15, 2026
Source: NVD

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertent...

Published: May 15, 2026
Source: NVD
CVE-2026-8669 MEDIUM - 6.5

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in t...

Published: May 15, 2026
Source: NVD