Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,607
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 12,061 - 12,080 of 36,815 CVEs
CVE-2026-42883 MEDIUM - 6.5

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in the URL path, but fetches downloadable items solely by attacker-provided IDs without constraining them...

Vendor: advplyr
Product: audiobookshelf
Published: May 11, 2026
Source: NVD

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with malicious content to funcionario/docdependente_upload.php, the application responds with an overly descriptive error message. This leads to information disclosure, effectively incre...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD
CVE-2026-42872 MEDIUM - 6.1

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_arquivos_etapa.php due to improper handling of user-supplied input. The id_processo parameter is directly embedded into the HTML without sanitization, ...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw was identified at the following endpoint: funcionario/profile_funcionario.php?id_funcionario=2. By injecting a malicious payload into the 'Description' (DescriΓ§Γ£o) field...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 11, 2026
Source: NVD
CVE-2026-42869 CRITICAL - 10.0

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET...

Vendor: socfortress
Product: CoPilot
Published: May 11, 2026
Source: NVD
CVE-2026-42050 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item. This vulnerability i...

Vendor: ImageMagick
Product: ImageMagick
Published: May 11, 2026
Source: NVD
CVE-2026-36734 HIGH - 8.8

EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient input validation, the attacker is able to execute arbitrary system commands on the device.

Published: May 11, 2026
Source: NVD
CVE-2026-2614 HIGH - 7.5

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the t...

Published: May 11, 2026
Source: NVD
CVE-2022-4988 HIGH - 7.3

Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images libraries that also have kn...

Published: May 11, 2026
Source: NVD

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerabili...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator access level) to inject HTML in Move Attachments admin page. This vulnerability is fixed in 2.28.2.

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-44635 HIGH - 7.5

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) β€” including type-safe cod...

Vendor: npm
Product: kysely
Published: May 11, 2026
Source: GitHub
CVE-2026-43979 MEDIUM - 5.0

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values β€” specifically title (sourced from research.title or research.query) and metadata key-value pairs β€”...

Vendor: pip
Product: local-deep-research
Published: May 11, 2026
Source: GitHub
CVE-2026-43898 CRITICAL - 10.0

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked ho...

Vendor: npm
Product: @nyariv/sandboxjs
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to download attachments on private bugnotes they should not be able to access, via the REST API en...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in MantisBT allows users having update_bug_threshold access (UPDATER, with default settings) to edit, change view state, and modify time tracking on bugnotes belonging to other users β€” bypa...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub

Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.0.0 to 2.28.1, lack of validation of filter_target parameter on return_dynamic_filters.php (normally used as an AJAX in View Issues Page) allows an attacker to inject arbitrary HTML if the target is a TEXTAREA custom field. This v...

Vendor: composer
Product: mantisbt/mantisbt
Published: May 11, 2026
Source: GitHub
CVE-2026-41159 MEDIUM - 5.3

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration op...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub
CVE-2026-41150 MEDIUM - 5.3

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then ...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diag...

Vendor: npm
Product: mermaid
Published: May 11, 2026
Source: GitHub