Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

911
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 1,098 CVEs

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

Vendor: composer
Product: twig/markdown-extra
Published: May 21, 2026
Source: GitHub

Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments

Vendor: composer
Product: twig/intl-extra
Published: May 21, 2026
Source: GitHub

Twig: The `spaceless` filter implicitly marks its output as safe

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

NocoDB: Stale Auth Cache After API Token Deletion

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub

NocoDB: Attachment Size Limit Bypass via Upload-by-URL

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub

NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation

Vendor: npm
Product: nocodb
Published: May 21, 2026
Source: GitHub

SpiceDB: Caveat structures with nested lists can result in improper cache reuse

Vendor: go
Product: github.com/authzed/spicedb
Published: May 21, 2026
Source: GitHub

Crawlee for Python: SSRF via sitemap-derived URLs

Vendor: pip
Product: crawlee
Published: May 21, 2026
Source: GitHub
CVE-2026-7837 LOW - 3.7

A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions.

Published: May 21, 2026
Source: NVD

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI se...

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors that would otherwise be caught and safely terminated by runtime protection.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-7836 LOW - 3.1

An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification via crafted hexadecimal input.

Published: May 21, 2026
Source: NVD
CVE-2026-7835 LOW - 3.1

A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.

Published: May 21, 2026
Source: NVD

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor service disruption under specific conditions.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character conversion requests.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption via crafted volume translation input.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmat...

Vendor: Siber Systems, Inc.
Product: Android App "RoboForm Password Manager"
Published: May 20, 2026
Source: NVD