Total CVEs

132,098

Critical Severity

2,824

High Severity

10,104

Last 7 Days

1,581
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,421 - 1,440 of 28,503 CVEs
CVE-2026-46614 CRITICAL - 9.8

Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46612 HIGH - 8.8

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46616 MEDIUM - 5.4

Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

Vendor: nuget
Product: Umbraco.Cms
Published: May 21, 2026
Source: GitHub
CVE-2026-46561 MEDIUM - 5.0

pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API

Vendor: pip
Product: pyload-ng
Published: May 21, 2026
Source: GitHub
CVE-2026-46545 HIGH - 7.5

nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item

Vendor: rust
Product: nimiq-primitives
Published: May 21, 2026
Source: GitHub
CVE-2026-46543 MEDIUM - 5.3

nimiq-blockchain: Genesis batch set request

Vendor: rust
Product: nimiq-blockchain
Published: May 21, 2026
Source: GitHub
CVE-2026-46542 MEDIUM - 4.3

nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points

Vendor: rust
Product: nimiq-keys
Published: May 21, 2026
Source: GitHub
CVE-2026-46539 MEDIUM - 5.9

nimiq-primitives: BlockInclusionProof interlink issue when hops are empty

Vendor: rust
Product: nimiq-primitives
Published: May 21, 2026
Source: GitHub
CVE-2026-46517 HIGH - 7.8

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

Vendor: pip
Product: lmdeploy
Published: May 21, 2026
Source: GitHub

Crawlee for Python: SSRF via sitemap-derived URLs

Vendor: pip
Product: crawlee
Published: May 21, 2026
Source: GitHub
CVE-2026-46473 HIGH - 7.5

Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Vendor: TCHATZI
Product: Authen::TOTP
Published: May 21, 2026
Source: NVD
CVE-2026-48249 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for outbound HTTPS requests issued during the mobile (RouteMate) login flow. ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48248 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for outbound HTTPS requests issued during the login/authentication flow. An attacker po...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48247 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for general-purpose outbound HTTPS requests issued by the shared helper functions. ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48246 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker pos...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48245 MEDIUM - 5.3

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Clo...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48244 MEDIUM - 5.3

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Goog...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48243 MEDIUM - 5.3

Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can extract the key and use it to make third-party API calls billed to or rate-limited against the original ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48242 HIGH - 8.1

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48241 HIGH - 8.1

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed insta...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD