Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

738
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,361 - 1,380 of 27,228 CVEs

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.

Published: May 14, 2026
Source: NVD
CVE-2026-46470 MEDIUM - 4.0

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

Vendor: GStreamer
Product: Good Plug-ins
Published: May 14, 2026
Source: NVD
CVE-2026-46469 MEDIUM - 4.0

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

Vendor: GStreamer
Product: Good Plug-ins
Published: May 14, 2026
Source: NVD
CVE-2026-42897 HIGH - 8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: exchange_server
Published: May 14, 2026
Source: NVD

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible to request paths such as http://localhost:8080/c:/Windows/System32/drivers/etc/hosts and have the cont...

Vendor: Badgerati
Product: Pode
Published: May 14, 2026
Source: NVD
CVE-2026-41615 CRITICAL - 9.6

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: authenticator
Published: May 14, 2026
Source: NVD
CVE-2025-15024 HIGH - 8.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Remote Code Inclusion. This issue affects Library Automation System: from v.19.5 be...

Vendor: Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.
Product: Library Automation System
Published: May 14, 2026
Source: NVD
CVE-2025-15023 HIGH - 8.8

Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Library Automation System: from v.19.5 bef...

Vendor: Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.
Product: Library Automation System
Published: May 14, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-3258. Reason: This candidate is a reservation duplicate of CVE-2026-3258. Notes: All CVE users should reference CVE-2026-3258instead of this candidate. All references and descriptions in this candidate have been rem...

Published: May 14, 2026
Source: NVD
CVE-2026-6923 LOW - 3.8

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.

Published: May 14, 2026
Source: NVD
CVE-2026-45448 MEDIUM - 4.3

CWE-601 URL redirection to untrusted site ('open redirect')

Vendor: ntop
Product: ntopng
Published: May 14, 2026
Source: NVD
CVE-2026-44827 HIGH - 8.8

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils....

Vendor: huggingface
Product: diffusers
Published: May 14, 2026
Source: NVD

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versions, an authenticated attacker could provide a URL pointing to internal/private IP ranges or localhos...

Vendor: nextcloud
Product: news
Published: May 14, 2026
Source: NVD

PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails after buf has already been freed, the Error label frees buf a second time, causing heap corr...

Vendor: podofo
Product: podofo
Published: May 14, 2026
Source: NVD
CVE-2026-20224 HIGH - 8.6

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper ...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: May 14, 2026
Source: NVD
CVE-2026-20210 MEDIUM - 5.4

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to reda...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: May 14, 2026
Source: NVD
CVE-2026-20209 MEDIUM - 5.4

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: May 14, 2026
Source: NVD
CVE-2026-20182 CRITICAL - 10.0

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Contr...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: May 14, 2026
Source: NVD

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the application to limited security risks under specific conditions.

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD