Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,741
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 11,301 - 11,320 of 36,811 CVEs
CVE-2020-37218 HIGH - 8.2

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwpla...

Vendor: Hdwplayer
Product: com_hdwplayer
Published: May 13, 2026
Source: NVD
CVE-2020-37217 MEDIUM - 4.3

Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the admin.php?action=add_user endpoint with POST requests containi...

Vendor: Easy2pilot-v7
Product: Easy2Pilot
Published: May 13, 2026
Source: NVD
CVE-2020-37174 MEDIUM - 5.5

WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design tab textfields. Attackers can inject JavaScript code through fields like 'Text for block toggle&...

Vendor: HUSKY
Product: Products Filter Professional for WooCommerce
Published: May 13, 2026
Source: NVD
CVE-2020-37169 MEDIUM - 5.5

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP fil...

Vendor: Ultimate Member
Product: ultimate-member
Published: May 13, 2026
Source: NVD
CVE-2020-37168 CRITICAL - 9.8

Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, the...

Vendor: Paiement
Product: Ecommerce Systempay
Published: May 13, 2026
Source: NVD
CVE-2026-45375 CRITICAL - 9.0

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings โ†’ Marketplace UI...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/getLocalGraph, POST /api/sync/setSyncInterval, POST /api/storage/updateRecentDocViewTime, POST /api/st...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45083 CRITICAL - 9.8

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the b...

Vendor: maven
Product: io.goobi.viewer:viewer-core
Published: May 13, 2026
Source: GitHub
CVE-2026-45152 HIGH - 7.8

uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files using /bin/bash -c. Because the check field is loaded directly from untrusted JSON metadata without va...

Vendor: go
Product: gitlab.com/uniget-org/cli
Published: May 13, 2026
Source: GitHub
CVE-2026-45148 MEDIUM - 4.3

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate metadata from documents that are invisible to the publish service. This vulnerability is fixed in 3....

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45147 MEDIUM - 4.3

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the handler performing a configuration write that is normally guarded by both. Any authenti...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45137 HIGH - 8.2

Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs ...

Vendor: rust
Product: anchor-lang
Published: May 13, 2026
Source: GitHub
CVE-2026-45136 HIGH - 7.8

claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-con...

Vendor: npm
Product: claude-code-cache-fix
Published: May 13, 2026
Source: GitHub
CVE-2026-44798 HIGH - 7.1

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the current_head field on the record, which was not intended to be user-editable. Doing so could cause Naut...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44797 HIGH - 8.5

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allo...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44796 MEDIUM - 6.5

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to application-wide denial of service via maliciously crafted regular expressions in the find field in co...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44794 MEDIUM - 5.4

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database t...

Vendor: pip
Product: nautobot
Published: May 13, 2026
Source: GitHub
CVE-2026-44774 MEDIUM - 9.9

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider a...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: May 13, 2026
Source: GitHub
CVE-2026-44740 MEDIUM - 6.5

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient v...

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 13, 2026
Source: GitHub
CVE-2026-45134 HIGH - 7.1

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt ma...

Vendor: pip
Product: langsmith
Published: May 13, 2026
Source: GitHub