Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

696
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,561 - 1,580 of 27,228 CVEs
CVE-2026-45053 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the we...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD

EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly into SQL queries via str_replace without any sanitization, enabling SQL injection through query par...

Vendor: phili67
Product: ecclesiacrm
Published: May 13, 2026
Source: NVD
CVE-2026-44381 MEDIUM - 5.3

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values from request parameters ...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD
CVE-2026-44380 HIGH - 7.2

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within th...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD
CVE-2026-44379 MEDIUM - 5.3

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID values, potentially causing integrity issues or u...

Vendor: MISP
Product: MISP
Published: May 13, 2026
Source: NVD
CVE-2026-44377 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty templa...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-44376 MEDIUM - 6.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.php, user input is reflected without sanitization only when a search returns exactly one product. This...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-39428 MEDIUM - 4.8

CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeCart v6.x. An attacker with administrative privileges can inject malicious JavaScript payloads into multiple fields during the creation or modification of a product. These payl...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-39358 HIGH - 7.2

CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sort_activity, sort_admin, and sort_customer) of the Products and Logs endpoints in CubeCart v6.x. This allows an attacker ...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-21821 HIGH - 8.3

The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses and increase the risk of client-side attacks...

Vendor: HCLSoftware
Product: BigFix SCM Reporting
Published: May 13, 2026
Source: NVD
CVE-2025-27853 HIGH - 7.3

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An a...

Published: May 13, 2026
Source: NVD
CVE-2025-27852 MEDIUM - 5.0

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary JavaScript code within the context of the WDU webpage. Full administrator level access to the device is ...

Published: May 13, 2026
Source: NVD
CVE-2025-27851 CRITICAL - 9.3

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate a...

Published: May 13, 2026
Source: NVD
CVE-2025-27850 HIGH - 7.5

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links when serving content. No mechanisms to restrict those link targets to a specific area of the filesys...

Published: May 13, 2026
Source: NVD
CVE-2026-33381 MEDIUM - 5.9

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-33380 MEDIUM - 6.3

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-33378 MEDIUM - 6.5

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-33377 HIGH - 7.1

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-33376 HIGH - 7.4

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD
CVE-2026-28383 MEDIUM - 6.5

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

Vendor: Grafana
Product: Grafana OSS
Published: May 13, 2026
Source: NVD