Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

612
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,841 - 1,860 of 27,228 CVEs

esm.sh: Legacy Route Path Traversal Can Lead to RCE

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: May 12, 2026
Source: GitHub
CVE-2026-8449 HIGH - 8.8

Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subau...

Published: May 12, 2026
Source: NVD
CVE-2026-45227 HIGH - 8.8

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __impo...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45226 HIGH - 7.1

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds poin...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-45225 HIGH - 7.6

Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted filename with traversal sequences. Attackers can exploit the unvalidated filename parameter in the u...

Vendor: heymrun
Product: heym
Published: May 12, 2026
Source: NVD
CVE-2026-44871 HIGH - 7.2

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying opera...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Wireless Operating System (AOS)
Published: May 12, 2026
Source: NVD
CVE-2026-44296 HIGH - 7.5

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and its first bytes do not parse as a valid TLS ClientH...

Vendor: deskflow
Product: deskflow
Published: May 12, 2026
Source: NVD
CVE-2026-44260 HIGH - 8.1

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no event handler c...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD
CVE-2026-44259 MEDIUM - 4.6

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security headers. Files with .html, .htm, or .svg extensions are served as text/html or image/svg+xml respectively,...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and home containment, but does not validate the dst (destination) parameter used by elfinder_paste. An attacker can copy or move files from within the home di...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and lands anywhere the Tomc...

Vendor: efwGrp
Product: efw4.X
Published: May 12, 2026
Source: NVD
CVE-2026-44015 HIGH - 8.5

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forward...

Vendor: 0xJacky
Product: nginx-ui
Published: May 12, 2026
Source: NVD
CVE-2026-42855 HIGH - 7.5

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp32 computes the authentication hash using the URI field from the client's Authorization header, ...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-42854 CRITICAL - 9.8

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP heade...

Vendor: espressif
Product: arduino-esp32
Published: May 12, 2026
Source: NVD
CVE-2026-42268 HIGH - 7.5

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @veri...

Vendor: owasp-modsecurity
Product: ModSecurity
Published: May 12, 2026
Source: NVD
CVE-2026-41195 MEDIUM - 5.0

mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker-controlled URL that the server later fetches. Because the server follows http/https redirects and do...

Vendor: mosparo
Product: mosparo
Published: May 12, 2026
Source: NVD
CVE-2026-35555 MEDIUM - 6.3

PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2026-33570 MEDIUM - 5.7

PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020
Published: May 12, 2026
Source: NVD
CVE-2026-26289 HIGH - 8.2

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.

Vendor: Subnet Solutions
Product: PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Published: May 12, 2026
Source: NVD
CVE-2026-44403 HIGH - 7.2

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session va...

Vendor: Wing FTP Server
Product: Wing FTP Server
Published: May 12, 2026
Source: NVD