Total CVEs

148,472

Critical Severity

4,701

High Severity

16,816

Last 7 Days

2,951
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 17,001 - 17,020 of 44,877 CVEs

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field on save, leaving it vulnerable to cross-site scripting (XSS). Kirby's list field stores its formatted content as HTML, and unlike other field t...

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection queries, allowing attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as password() (dis...

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorization against the stored script's permission by ID, but whe...

Vendor: npm
Product: fuxa-server
Published: May 26, 2026
Source: GitHub

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.

Vendor: npm
Product: fuxa-server
Published: May 26, 2026
Source: GitHub

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled ...

Vendor: npm
Product: @frangoteam/fuxa
Published: May 26, 2026
Source: GitHub
CVE-2026-42568 MEDIUM - 4.3

Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515 escaping. Versions 5.13....

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 26, 2026
Source: GitHub
CVE-2026-42462 HIGH - 7.0

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linke...

Vendor: npm
Product: @fedify/fedify
Published: May 26, 2026
Source: GitHub
CVE-2026-9604 MEDIUM - 4.3

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. U...

Published: May 26, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: May 26, 2026
Source: NVD
CVE-2026-8647 MEDIUM - 4.8

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when none of the Perl modules Crypt::PRNG, Crypt::OpenSSL::Random, Net::SSLeay, Crypt::Random, or Bytes::...

Published: May 26, 2026
Source: NVD
CVE-2026-46740 MEDIUM - 5.3

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd...

Vendor: RRWO
Product: Mojolicious::Plugin::Statsd
Published: May 26, 2026
Source: NVD
CVE-2026-42089 HIGH - 8.6

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass at...

Vendor: npm
Product: yeoman-environment
Published: May 26, 2026
Source: GitHub
CVE-2026-41207 MEDIUM - 5.3

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distinguish success from failure. Since this output is used as HKDF key material for the response AEAD, a ...

Vendor: maven
Product: io.netty.incubator:netty-incubator-codec-ohttp
Published: May 26, 2026
Source: GitHub
CVE-2026-9603 MEDIUM - 6.5

A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been...

Published: May 26, 2026
Source: NVD
CVE-2026-9584 HIGH - 7.3

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and ...

Published: May 26, 2026
Source: NVD
CVE-2026-5260 HIGH - 8.2

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

Published: May 26, 2026
Source: NVD
CVE-2026-48710 MEDIUM - 6.5

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed hea...

Vendor: Kludex
Product: starlette
Published: May 26, 2026
Source: NVD
CVE-2026-44905 HIGH - 7.5

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically val...

Vendor: riebl
Product: vanetza
Published: May 26, 2026
Source: NVD

Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting ...

Vendor: prometheus
Product: prometheus
Published: May 26, 2026
Source: NVD
CVE-2026-43988 HIGH - 7.5

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing corrupted ASN.1/OER structures (e.g., invalid length fi...

Vendor: riebl
Product: vanetza
Published: May 26, 2026
Source: NVD