Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,806
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 11,161 - 11,180 of 36,811 CVEs
CVE-2026-33377 HIGH - 7.1

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-33376 HIGH - 7.4

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-28383 MEDIUM - 6.5

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-28380 MEDIUM - 6.5

Any Editor could delete any snapshot, even if they have no access to read or write them.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-28379 MEDIUM - 6.5

A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-28376 MEDIUM - 6.5

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-28374 MEDIUM - 4.3

Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD

A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet.

Published: May 13, 2026
Source: NVD

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidation step in the users-permissions and admin authenti...

Vendor: npm
Product: @strapi/admin
Published: May 13, 2026
Source: GitHub
CVE-2026-22599 CRITICAL - 7.2

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could inject arbitrary datab...

Vendor: npm
Product: @strapi/content-type-builder
Published: May 13, 2026
Source: GitHub
CVE-2025-64526 MEDIUM - 5.3

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on routes whose body schema does not contain an `email` field (`/auth...

Vendor: npm
Product: @strapi/plugin-users-permissions
Published: May 13, 2026
Source: GitHub
CVE-2026-8496 MEDIUM - 6.1

A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS...

Published: May 13, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in src/cowboy_req.erl accumulates incoming request bytes into a Buffer binary with no upper-bound che...

Published: May 13, 2026
Source: NVD

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion. cow_spdy:inflate/2 in cowlib passes peer-supplied compressed bytes directly to zlib:inflate/2 with no output size bound. The SPDY...

Vendor: ninenines
Product: cowlib
Published: May 13, 2026
Source: NVD

Rejected reason: REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-40520. Reason: This candidate is a duplicate of CVE-2026-40520. Notes: All CVE users should reference CVE-2026-40520 instead of this candidate.

Published: May 13, 2026
Source: NVD

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.

Vendor: Arqit
Product: Symmetric Key Agreement Platform
Published: May 13, 2026
Source: NVD
CVE-2026-33584 MEDIUM - 5.3

Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Symmetric Key Agreement Platform: before 26.03.

Vendor: Arqit
Product: Symmetric Key Agreement Platform
Published: May 13, 2026
Source: NVD
CVE-2026-33583 HIGH - 8.7

Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Agreement Platform. This issue affects Symmetric Key Agreement Platform: before 26.03.

Vendor: Arqit
Product: Symmetric Key Agreement Platform
Published: May 13, 2026
Source: NVD
CVE-2026-30906 HIGH - 7.8

Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

Vendor: Zoom Communications
Product: Zoom Rooms
Published: May 13, 2026
Source: NVD
CVE-2026-30905 HIGH - 7.8

External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.

Vendor: Zoom Communications
Product: Zoom Workplace VDI Plugin
Published: May 13, 2026
Source: NVD