Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

899
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 121 - 140 of 27,228 CVEs

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF === true), which normally re...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files o...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a list of every page that references that file, includ...

Published: May 21, 2026
Source: NVD
CVE-2026-47102 HIGH - 8.8

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin,...

Vendor: BerriAI
Product: litellm
Published: May 21, 2026
Source: NVD
CVE-2026-47101 HIGH - 8.8

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created wi...

Vendor: BerriAI
Product: litellm
Published: May 21, 2026
Source: NVD
CVE-2026-46673 HIGH - 7.5

Russh: Unchecked CryptoVec allocation and growth handling is reachable

Vendor: rust
Product: russh-cryptovec
Published: May 21, 2026
Source: GitHub
CVE-2026-46609 MEDIUM - 4.6

Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog

Vendor: nuget
Product: Umbraco.Cms
Published: May 21, 2026
Source: GitHub
CVE-2026-46556 MEDIUM - 6.5

FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

Vendor: pip
Product: flaskbb
Published: May 21, 2026
Source: GitHub

NocoDB: Stale Auth Cache After API Token Deletion

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub

NocoDB: Attachment Size Limit Bypass via Upload-by-URL

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46552 MEDIUM - 5.8

NocoDB: Shared-base link access can invite arbitrary users as persistent base members

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46551 MEDIUM - 6.5

NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46550 MEDIUM - 5.4

NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub

NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46548 MEDIUM - 4.3

NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46547 MEDIUM - 6.1

NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub
CVE-2026-46519 HIGH - 8.8

MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement

Vendor: npm
Product: mcp-server-kubernetes
Published: May 21, 2026
Source: GitHub

SpiceDB: Caveat structures with nested lists can result in improper cache reuse

Vendor: go
Product: github.com/authzed/spicedb
Published: May 21, 2026
Source: GitHub

Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss

Vendor: rust
Product: p3-challenger
Published: May 21, 2026
Source: GitHub

Snappy: Binary path is never shell-escaped due to an inverted is_executable check

Vendor: composer
Product: KnpLabs/knp-snappy
Published: May 21, 2026
Source: GitHub