Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

738
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,381 - 1,400 of 27,228 CVEs
CVE-2025-62313 MEDIUM - 5.4

HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions.

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse, especially if not combined with secure transmission practices.

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD
CVE-2025-62311 MEDIUM - 4.3

HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD
CVE-2025-62310 MEDIUM - 5.4

HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions.

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions.

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD
CVE-2025-62308 MEDIUM - 5.1

HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under certain conditions

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD
CVE-2025-62305 MEDIUM - 5.1

HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions.

Vendor: HCL
Product: AION
Published: May 14, 2026
Source: NVD
CVE-2026-44899 MEDIUM - 4.7

Mistune Image Directive CSS Injection Vulnerability

Vendor: pip
Product: mistune
Published: May 14, 2026
Source: GitHub
CVE-2026-44898 MEDIUM - 6.1

Mistune TOC Anchor Injection XSS

Vendor: pip
Product: mistune
Published: May 14, 2026
Source: GitHub
CVE-2026-45292 MEDIUM - 5.3

OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation

Vendor: maven
Product: io.opentelemetry:opentelemetry-api
Published: May 14, 2026
Source: GitHub

Portainer missing authorization on custom template file endpoint, which exposes template content

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer: JWT accepted in URL query leaks tokens to logs and referers

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer has an endpoint security bypass via Swarm service create/update

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44882 HIGH - 8.1

Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44850 HIGH - 8.5

Portainer has a bind-mount restriction bypass via HostConfig.Mounts

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44885 MEDIUM - 5.5

Portainer has a path traversal in backup archive extraction that allows arbitrary file write

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer missing authorization on Docker plugin endpoints, which allows host RCE

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub