Total CVEs

148,841

Critical Severity

4,744

High Severity

16,941

Last 7 Days

3,054
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 18,401 - 18,420 of 45,246 CVEs
CVE-2026-4293 MEDIUM - 5.3

The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the attacker to control the browser.

Published: May 20, 2026
Source: NVD
CVE-2026-39047 HIGH - 7.5

Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100

Published: May 20, 2026
Source: NVD
CVE-2025-32750 HIGH - 7.5

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Vendor: Dell
Product: PowerFlex Manager (Appliance), PowerFlex Manager (Rack), PowerFlex Manager
Published: May 20, 2026
Source: NVD
CVE-2023-7346 MEDIUM - 4.0

Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that...

Published: May 20, 2026
Source: NVD
CVE-2026-46431 MEDIUM - 4.3

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's Origin. Because EventSource does not preflight and does not send cookies, the wildcard is su...

Vendor: go
Product: github.com/xyproto/algernon
Published: May 20, 2026
Source: GitHub
CVE-2026-46430 MEDIUM - 4.3

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553&...

Vendor: go
Product: github.com/xyproto/algernon
Published: May 20, 2026
Source: GitHub

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.1...

Vendor: npm
Product: @cap-js/sqlite
Published: May 20, 2026
Source: GitHub
CVE-2026-46420 MEDIUM - 5.6

setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through platform-overrides.php, and compos...

Vendor: actions
Product: shivammathur/setup-php
Published: May 20, 2026
Source: GitHub
CVE-2026-45804 HIGH - 7.5

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change,...

Vendor: pip
Product: diffusers
Published: May 20, 2026
Source: GitHub

rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK automatically loads .rtk/filters.toml from the working directory with highest priority and without user notification. An at...

Vendor: rust
Product: rtk
Published: May 20, 2026
Source: GitHub
CVE-2026-8485 MEDIUM - 5.9

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Vendor: progress
Product: moveit_automation
Published: May 20, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BEAM atom table exhaustion. Multiple LiveView event handlers convert user-supplied event parameter strings to atoms using String.to_atom/1 without valid...

Vendor: erlang
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler in 'Elixir.PhoenixStorybook.Story.PlaygroundPreviewLive':handle_ev...

Vendor: erlang
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD

Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storybook/live/story/component_iframe...

Vendor: phenixdigital
Product: phoenix_storybook
Published: May 20, 2026
Source: NVD
CVE-2026-24425 HIGH - 8.8

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fa...

Vendor: twigphp
Product: Twig
Published: May 20, 2026
Source: NVD
CVE-2026-22554 HIGH - 7.8

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability

Vendor: MediaArea
Product: MediaInfoLib
Published: May 20, 2026
Source: NVD
CVE-2026-21836 MEDIUM - 6.5

The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability.  Under certain circumstances, document level access restrictions will be ignored when determining what data to return from an AI query.  This could enable an authenticated attacker to view sensitive data.

Vendor: HCLSoftware
Product: DominoIQ
Published: May 20, 2026
Source: NVD
CVE-2026-5950 MEDIUM - 5.3

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through ...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-5947 HIGH - 7.5

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients" limit is reached (as would occur during...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-5946 HIGH - 7.5

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code pat...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD