Total CVEs

131,459

Critical Severity

2,797

High Severity

9,990

Last 7 Days

1,107
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,421 - 1,440 of 27,864 CVEs
CVE-2026-45246 MEDIUM - 5.5

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default filesystem permissions. When the refresh-free path rewrites the configuration file, it creates the r...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-45245 HIGH - 7.4

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. ...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-45244 MEDIUM - 5.4

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation feature is enabled. Attackers can influence the agent through malicious page or summary content to invoke ...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-21789 MEDIUM - 4.6

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Vendor: HCLSoftware
Product: Connections
Published: May 18, 2026
Source: NVD

OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45681 MEDIUM - 5.9

OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45680 MEDIUM - 5.9

OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-8836 CRITICAL - 9.8

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be i...

Published: May 18, 2026
Source: NVD
CVE-2026-45243 MEDIUM - 6.1

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runtime messages with spoofed sender identifiers to list, read, crea...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-45242 HIGH - 7.1

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slidesDir request parameter. Attackers can exploit thi...

Vendor: steipete
Product: summarize
Published: May 18, 2026
Source: NVD
CVE-2026-45231 MEDIUM - 6.1

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side sanitization and rendered using innerHTML without client-side escaping. Attackers can create or update a...

Vendor: DumbWareio
Product: DumbAssets
Published: May 18, 2026
Source: NVD

AVideo: Authenticated Arbitrary File Read in view/update.php

Vendor: composer
Product: WWBN/AVideo
Published: May 18, 2026
Source: GitHub
CVE-2026-45495 HIGH - 8.8

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Vendor: microsoft
Product: edge_chromium
Published: May 18, 2026
Source: NVD
CVE-2026-45494 MEDIUM - 5.4

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Vendor: microsoft
Product: edge_chromium
Published: May 18, 2026
Source: NVD
CVE-2026-45492 MEDIUM - 5.4

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Vendor: microsoft
Product: edge_chromium
Published: May 18, 2026
Source: NVD
CVE-2026-45230 CRITICAL - 9.1

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the o...

Vendor: DumbWareio
Product: DumbAssets
Published: May 18, 2026
Source: NVD
CVE-2026-42822 CRITICAL - 10.0

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_local
Published: May 18, 2026
Source: NVD
CVE-2026-32849 MEDIUM - 5.5

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_l...

Vendor: NetBSD
Product: src
Published: May 18, 2026
Source: NVD
CVE-2026-32848 MEDIUM - 4.7

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mu...

Vendor: NetBSD
Product: src
Published: May 18, 2026
Source: NVD
CVE-2026-29965 MEDIUM - 6.1

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscated JavaScript syntax.

Vendor: hsclabs
Product: mailinspector
Published: May 18, 2026
Source: NVD