Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

911
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 9,438 CVEs
CVE-2026-47125 HIGH - 8.8

Arcane: Missing admin authorization on global variables endpoint

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 23, 2026
Source: GitHub

Parse Server: Pre-authentication denial of service via client version header regex backtracking

Vendor: npm
Product: parse-server
Published: May 23, 2026
Source: GitHub
CVE-2026-46717 HIGH - 8.5

Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 23, 2026
Source: GitHub
CVE-2026-9011 HIGH - 7.5

The Ditty โ€“ Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated...

Published: May 22, 2026
Source: NVD
CVE-2026-8679 HIGH - 7.5

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or ...

Published: May 22, 2026
Source: NVD
CVE-2026-9018 HIGH - 8.8

The Easy Elements for Elementor โ€“ Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-co...

Published: May 22, 2026
Source: NVD
CVE-2026-4834 HIGH - 7.5

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published: May 22, 2026
Source: NVD
CVE-2026-34911 HIGH - 7.7

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.

Published: May 22, 2026
Source: NVD
CVE-2026-46701 HIGH - 7.6

Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

Vendor: npm
Product: network-ai
Published: May 21, 2026
Source: GitHub

@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty

Vendor: npm
Product: @nevware21/ts-utils
Published: May 21, 2026
Source: GitHub

containerd user ID handling bypass allows runAsNonRoot evasion

Vendor: go
Product: github.com/containerd/containerd
Published: May 21, 2026
Source: GitHub
CVE-2026-46679 HIGH - 7.5

js-libp2p: Memory DoS via subscription flood of unique topics

Vendor: npm
Product: @libp2p/gossipsub
Published: May 21, 2026
Source: GitHub

Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: Sandbox property and method bypass via object-destructuring assignment

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub
CVE-2026-46625 HIGH - 7.5

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

Vendor: npm
Product: js-cookie
Published: May 21, 2026
Source: GitHub
CVE-2026-47102 HIGH - 8.8

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin,...

Vendor: BerriAI
Product: litellm
Published: May 21, 2026
Source: NVD
CVE-2026-47101 HIGH - 8.8

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created wi...

Vendor: BerriAI
Product: litellm
Published: May 21, 2026
Source: NVD
CVE-2026-46673 HIGH - 7.5

Russh: Unchecked CryptoVec allocation and growth handling is reachable

Vendor: rust
Product: russh-cryptovec
Published: May 21, 2026
Source: GitHub
CVE-2026-46519 HIGH - 8.8

MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement

Vendor: npm
Product: mcp-server-kubernetes
Published: May 21, 2026
Source: GitHub

Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss

Vendor: rust
Product: p3-challenger
Published: May 21, 2026
Source: GitHub