Total CVEs

131,518

Critical Severity

2,798

High Severity

10,013

Last 7 Days

1,113
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,781 - 1,800 of 27,923 CVEs
CVE-2026-23695 MEDIUM - 5.4

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html direct...

Vendor: Cockpit-HQ
Product: Cockpit
Published: May 15, 2026
Source: NVD
CVE-2026-45106 MEDIUM - 4.6

Weblate: Stored HTML injection in editor search preview

Vendor: pip
Product: weblate
Published: May 15, 2026
Source: GitHub
CVE-2026-45062 HIGH - 8.1

FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files

Vendor: go
Product: github.com/dunglas/frankenphp
Published: May 15, 2026
Source: GitHub
CVE-2026-44716 HIGH - 7.5

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

Vendor: pip
Product: pipecat-ai
Published: May 15, 2026
Source: GitHub
CVE-2026-41147 HIGH - 8.7

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Request class. The application relies primarily on client-side filtering to sanitize HTML tags and attri...

Vendor: composer
Product: nukeviet/nukeviet
Published: May 15, 2026
Source: GitHub
CVE-2026-40092 HIGH - 7.5

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, Ke...

Vendor: rust
Product: nimiq-keys
Published: May 15, 2026
Source: GitHub
CVE-2026-22810 HIGH - 8.2

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded fil...

Vendor: npm
Product: @joplin/onenote-converter
Published: May 15, 2026
Source: GitHub
CVE-2025-65954 MEDIUM - 4.7

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the br...

Vendor: composer
Product: simplesamlphp/simplesamlphp-module-casserver
Published: May 15, 2026
Source: GitHub
CVE-2026-46508 HIGH - 7.8

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and tas...

Vendor: vercel
Product: turborepo
Published: May 15, 2026
Source: NVD

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using gh run view --log or gh run view --log-failed. The vulnerability...

Vendor: cli
Product: cli
Published: May 15, 2026
Source: NVD
CVE-2026-45773 MEDIUM - 6.5

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send...

Vendor: vercel
Product: turborepo
Published: May 15, 2026
Source: NVD
CVE-2026-45772 CRITICAL - 9.8

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package manager detection exe...

Vendor: vercel, @turbo
Product: turborepo, codemod, workspaces
Published: May 15, 2026
Source: NVD
CVE-2026-35194 HIGH - 8.1

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE exp...

Vendor: Apache Software Foundation
Product: Apache Flink
Published: May 15, 2026
Source: NVD

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertent...

Published: May 15, 2026
Source: NVD
CVE-2026-8669 MEDIUM - 6.5

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in t...

Published: May 15, 2026
Source: NVD

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the...

Vendor: vim
Product: vim
Published: May 15, 2026
Source: NVD
CVE-2026-45736 MEDIUM - 4.4

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.

Vendor: websockets
Product: ws
Published: May 15, 2026
Source: NVD
CVE-2026-39054 HIGH - 7.3

Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operati...

Published: May 15, 2026
Source: NVD
CVE-2026-39053 MEDIUM - 6.5

Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...), unsafe XML processing can lead to file disclosure or SSRF...

Published: May 15, 2026
Source: NVD
CVE-2026-39052 MEDIUM - 6.5

Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or allowlist restricti...

Published: May 15, 2026
Source: NVD