Total CVEs

131,459

Critical Severity

2,797

High Severity

9,990

Last 7 Days

1,107
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,401 - 1,420 of 27,864 CVEs
CVE-2026-27130 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input sanitization, lack of schema validation and direct shell interpolation. User-controlled application ...

Vendor: Dokploy
Product: dokploy
Published: May 18, 2026
Source: NVD

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected fi...

Vendor: FreePBX
Product: security-reporting
Published: May 18, 2026
Source: NVD
CVE-2026-46559 MEDIUM - 4.0

ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46557 MEDIUM - 6.2

ImageMagick: Stack overflow in fx operation

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46523 MEDIUM - 6.2

ImageMagick: Use-After-Free in MSL decoder.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46522 HIGH - 7.5

ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46521 MEDIUM - 5.5

ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-46520 HIGH - 7.5

ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45664 MEDIUM - 5.3

ImageMagick: Policy Bypass in MNG coder could

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45624 MEDIUM - 5.1

ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: May 18, 2026
Source: GitHub
CVE-2026-45367 HIGH - 7.5

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
Published: May 18, 2026
Source: GitHub
CVE-2026-45554 MEDIUM - 5.3

NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes

Vendor: pip
Product: nicegui
Published: May 18, 2026
Source: GitHub
CVE-2026-45553 HIGH - 7.5

NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()

Vendor: pip
Product: nicegui
Published: May 18, 2026
Source: GitHub
CVE-2026-45686 HIGH - 7.5

OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45685 HIGH - 7.5

OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45684 MEDIUM - 4.9

OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45682 MEDIUM - 5.1

OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-47092 HIGH - 7.8

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version ch...

Vendor: jarrodwatts
Product: claude-hud
Published: May 18, 2026
Source: NVD

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin JSON. Attackers can access any file readable by the process and the file metadata is written to a pe...

Vendor: jarrodwatts
Product: claude-hud
Published: May 18, 2026
Source: NVD
CVE-2026-47090 MEDIUM - 4.6

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded values, allowing attackers to inject arbitrary ANSI codes into terminal sessions. Attackers can embe...

Vendor: jarrodwatts
Product: claude-hud
Published: May 18, 2026
Source: NVD