Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,978
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,121 - 1,140 of 3,419 CVEs
CVE-2026-7414 CRITICAL - 9.8

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or removed by end users, enabling trivial unauthorized access to device management interfaces by anyone w...

Vendor: yarbo
Product: lawn_mower_firmware
Published: May 07, 2026
Source: NVD
CVE-2025-63704 CRITICAL - 9.8

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

Published: May 07, 2026
Source: NVD
CVE-2025-63703 CRITICAL - 9.8

npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

Published: May 07, 2026
Source: NVD
CVE-2026-36458 CRITICAL - 9.8

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered.

Published: May 07, 2026
Source: NVD
CVE-2025-63706 CRITICAL - 9.8

NPM package next-npm-version1.0.1 is vulnerable to Command injection.

Published: May 07, 2026
Source: NVD
CVE-2026-6795 CRITICAL - 9.6

URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

Published: May 07, 2026
Source: NVD
CVE-2026-41589 CRITICAL - 9.6

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and...

Vendor: charmbracelet
Product: wish
Published: May 07, 2026
Source: NVD
CVE-2026-30496 CRITICAL - 9.8

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports both reading configuration (74 endpoints) and writing/modifying settings including volume, mute, brightn...

Published: May 07, 2026
Source: NVD
CVE-2026-8094 CRITICAL - 9.8

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Vendor: mozilla
Product: firefox
Published: May 07, 2026
Source: NVD
CVE-2026-8091 CRITICAL - 9.8

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

Vendor: mozilla
Product: firefox
Published: May 07, 2026
Source: NVD
CVE-2026-5791 CRITICAL - 9.6

Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

Published: May 07, 2026
Source: NVD
CVE-2026-6508 CRITICAL - 9.8

Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liderahenk: from 2.0.1 before 2.0.2.

Published: May 07, 2026
Source: NVD
CVE-2026-33587 CRITICAL - 10.0

Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.

Vendor: Open Notebook
Product: Open Notebook
Published: May 07, 2026
Source: NVD
CVE-2026-44007 CRITICAL - 9.1

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration โ€” including require: false. With access to vm2, the sandbox constructs a new i...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-42217 CRITICAL - 9.8

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: May 07, 2026
Source: NVD
CVE-2026-42216 CRITICAL - 9.1

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed r...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: May 07, 2026
Source: NVD
CVE-2026-40982 CRITICAL - 9.1

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1....

Vendor: Spring
Product: Spring Cloud Config
Published: May 07, 2026
Source: NVD
CVE-2026-43999 CRITICAL - 9.9

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host con...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-44005 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-contro...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-43997 CRITICAL - 10.0

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability ...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub