Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

899
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 141 - 160 of 27,228 CVEs

Snappy : SSRF and local file read via the xsl-style-sheet option

Vendor: composer
Product: knplabs/knp-snappy
Published: May 21, 2026
Source: GitHub

Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-4843 MEDIUM - 4.3

The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access an...

Published: May 21, 2026
Source: NVD
CVE-2026-47114 HIGH - 8.8

IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes...

Vendor: iina
Product: iina
Published: May 21, 2026
Source: NVD

Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46614 CRITICAL - 9.8

Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46612 HIGH - 8.8

Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives

Vendor: go
Product: github.com/fission/fission
Published: May 21, 2026
Source: GitHub
CVE-2026-46616 MEDIUM - 5.4

Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

Vendor: nuget
Product: Umbraco.Cms
Published: May 21, 2026
Source: GitHub
CVE-2026-46561 MEDIUM - 5.0

pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API

Vendor: pip
Product: pyload-ng
Published: May 21, 2026
Source: GitHub
CVE-2026-46545 HIGH - 7.5

nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item

Vendor: rust
Product: nimiq-primitives
Published: May 21, 2026
Source: GitHub
CVE-2026-46543 MEDIUM - 5.3

nimiq-blockchain: Genesis batch set request

Vendor: rust
Product: nimiq-blockchain
Published: May 21, 2026
Source: GitHub
CVE-2026-46542 MEDIUM - 4.3

nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points

Vendor: rust
Product: nimiq-keys
Published: May 21, 2026
Source: GitHub
CVE-2026-46539 MEDIUM - 5.9

nimiq-primitives: BlockInclusionProof interlink issue when hops are empty

Vendor: rust
Product: nimiq-primitives
Published: May 21, 2026
Source: GitHub
CVE-2026-46517 HIGH - 7.8

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

Vendor: pip
Product: lmdeploy
Published: May 21, 2026
Source: GitHub

Crawlee for Python: SSRF via sitemap-derived URLs

Vendor: pip
Product: crawlee
Published: May 21, 2026
Source: GitHub
CVE-2026-46473 HIGH - 7.5

Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Vendor: TCHATZI
Product: Authen::TOTP
Published: May 21, 2026
Source: NVD
CVE-2026-48249 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for outbound HTTPS requests issued during the mobile (RouteMate) login flow. ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48248 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for outbound HTTPS requests issued during the login/authentication flow. An attacker po...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48247 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for general-purpose outbound HTTPS requests issued by the shared helper functions. ...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD
CVE-2026-48246 MEDIUM - 5.9

Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker pos...

Vendor: Open ISES
Product: Tickets
Published: May 21, 2026
Source: NVD