Total CVEs

131,397

Critical Severity

2,785

High Severity

9,965

Last 7 Days

1,101
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,141 - 1,160 of 27,802 CVEs
CVE-2026-33642 CRITICAL - 9.9

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/W...

Vendor: kovidgoyal
Product: kitty
Published: May 19, 2026
Source: NVD
CVE-2026-32738 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an e...

Vendor: strukturag
Product: libheif
Published: May 19, 2026
Source: NVD
CVE-2026-8605 CRITICAL - 9.8

In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8604 HIGH - 8.8

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8603 CRITICAL - 9.8

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD
CVE-2026-8602 CRITICAL - 9.1

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

Vendor: scadabr
Product: scadabr
Published: May 19, 2026
Source: NVD

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads toย Remote Code Execution (RCE), potentially allowing code execution on the affected system

Published: May 19, 2026
Source: NVD
CVE-2026-47107 CRITICAL - 9.6

Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certifica...

Vendor: windmill-labs
Product: windmill
Published: May 19, 2026
Source: NVD
CVE-2026-33633 HIGH - 7.5

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a...

Vendor: kovidgoyal
Product: kitty
Published: May 19, 2026
Source: NVD
CVE-2026-32134 MEDIUM - 5.9

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the broker can crash due to a NULL pointer dereference during MQTT session resumption for clean_start=0 cli...

Vendor: nanomq
Product: nanomq, NanoNNG
Published: May 19, 2026
Source: NVD
CVE-2025-61081 HIGH - 7.5

In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is permanently available. The authentication key enables flash to the Electronic Parking Break (EPB) and Supplemental Restoration System (SRS) related ECUs.

Published: May 19, 2026
Source: NVD

In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.ย  An authenticated attacker with administrative privileges could exploit this issue to confirm the pre...

Published: May 19, 2026
Source: NVD
CVE-2026-47358 HIGH - 7.5

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates vi...

Vendor: tenable
Product: Terrascan
Published: May 19, 2026
Source: NVD
CVE-2026-47357 HIGH - 7.5

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled ...

Vendor: tenable
Product: Terrascan
Published: May 19, 2026
Source: NVD
CVE-2026-47356 HIGH - 7.5

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_ur...

Vendor: tenable
Product: Terrascan
Published: May 19, 2026
Source: NVD
CVE-2026-36829 CRITICAL - 9.8

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled cookie value without proper sanitization, allowing directory traversal and bypas...

Published: May 19, 2026
Source: NVD
CVE-2026-36828 HIGH - 8.8

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.

Published: May 19, 2026
Source: NVD
CVE-2026-36827 MEDIUM - 5.4

A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters to it. The helper performs unsafe argument processing using eval, which allows command injection when...

Published: May 19, 2026
Source: NVD
CVE-2026-46341 MEDIUM - 6.1

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching

Vendor: npm
Product: @apify/actors-mcp-server
Published: May 19, 2026
Source: GitHub
CVE-2026-46426 HIGH - 7.6

Budibase: Unrestricted Upload of File with Dangerous Type

Vendor: npm
Product: budibase
Published: May 19, 2026
Source: GitHub