Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,589
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 12,141 - 12,160 of 36,815 CVEs
CVE-2026-42858 HIGH - 8.5

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed directly to requests.get() i...

Vendor: openedx
Product: openedx-platform
Published: May 11, 2026
Source: NVD
CVE-2026-42857 MEDIUM - 4.6

Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove <style> tags from user-generated discussion post content. This content is rendered with Django's |safe ...

Vendor: openedx
Product: openedx-platform
Published: May 11, 2026
Source: NVD
CVE-2026-42316 MEDIUM - 6.5

kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping e...

Vendor: Azure
Product: kafka-sink-azure-kusto
Published: May 11, 2026
Source: NVD
CVE-2026-41431 HIGH - 8.0

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signature...

Vendor: zen-browser
Product: desktop
Published: May 11, 2026
Source: NVD
CVE-2026-41257 MEDIUM - 5.5

jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond โ‰ˆ1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used ...

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD
CVE-2026-41256 MEDIUM - 5.5

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \x00 and arbitrary suffix compiles and executes as only the prefix before the...

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD
CVE-2026-41250 MEDIUM - 5.7

Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.

Vendor: taigaio
Product: taiga-front
Published: May 11, 2026
Source: NVD
CVE-2026-40612 MEDIUM - 5.5

jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted.

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD
CVE-2026-3609 HIGH - 7.8

Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cross reference to KVE 2023-5589 (https://krcert.or.kr)

Vendor: wellbia
Product: xigncode3
Published: May 11, 2026
Source: NVD

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

Published: May 11, 2026
Source: NVD
CVE-2026-38569 MEDIUM - 5.4

HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add or POST /feedback/add.

Published: May 11, 2026
Source: NVD
CVE-2026-38568 HIGH - 8.1

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve records by the user-supplied ID without verifying that the requesting user is the owner o...

Published: May 11, 2026
Source: NVD
CVE-2026-38567 CRITICAL - 9.8

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker can bypass authentication by supplying a crafted username (e.g. admin'--) or extract the full con...

Published: May 11, 2026
Source: NVD
CVE-2026-38566 HIGH - 8.1

HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission at /feedback/add/<id>, interview scheduling at /interviews/add) are vulnerable to CSRF. A...

Published: May 11, 2026
Source: NVD
CVE-2026-36983 HIGH - 7.3

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

Vendor: dlink
Product: dcs-932l_firmware
Published: May 11, 2026
Source: NVD
CVE-2026-36962 HIGH - 7.3

SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution by writing malicious files to the server's file system via the keyword parameter in the /index/...

Published: May 11, 2026
Source: NVD
CVE-2026-34095 MEDIUM - 6.1

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD
CVE-2026-34093 MEDIUM - 5.3

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Vendor: Wikimedia Foundation
Product: MediaWiki
Published: May 11, 2026
Source: NVD
CVE-2026-30635 HIGH - 8.1

Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/server.js when a user reads from an external FORGE_BASE_URL.

Published: May 11, 2026
Source: NVD