CVEs from 2026

14,035 normalized CVEs published or assigned in this year.

Total
14,035
critical
critical 1,231
high
high 4,634
medium
medium 4,444
low
low 484
% Critical
8.8%
% with KEV
0.4%
% with exploit
0.7%

Top vendors

Top products

  • chrome 522
  • firepower_threat_defense_software 300
  • firepower_threat_defense 298
  • gcp 239
  • openclaw 172
  • commerce 104
  • commerce_b2b 89
  • grafana 80
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-45403 low 2.5 2.5 6d ago AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only …
CVE-2026-45570 low 2.5 7d ago go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in …
CVE-2026-35202 low 2.5 8d ago Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocat…
CVE-2026-46554 low 2.5 13d ago NocoDB: Stale Auth Cache After API Token Deletion
CVE-2026-46553 low 2.5 13d ago NocoDB: Attachment Size Limit Bypass via Upload-by-URL
CVE-2026-46549 low 2.5 13d ago NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-46668 low 2.5 13d ago SpiceDB: Caveat structures with nested lists can result in improper cache reuse
CVE-2026-46497 low 2.5 13d ago Crawlee for Python: SSRF via sitemap-derived URLs
CVE-2026-46635 low 2.5 14d ago Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
CVE-2026-45133 low 2.5 14d ago Symfony hardened the parser when handling untrusted input
CVE-2026-45071 low 2.5 14d ago Symfony has XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
CVE-2026-46629 low 2.5 14d ago twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
CVE-2026-46628 low 2.5 14d ago Twig: The `spaceless` filter implicitly marks its output as safe
CVE-2026-46637 low 2.5 14d ago Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVE-2026-45072 low 2.5 14d ago Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
CVE-2026-45305 low 2.5 14d ago Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
CVE-2026-45304 low 2.5 14d ago Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
CVE-2026-46342 low 2.5 15d ago Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
CVE-2026-45739 low 2.5 15d ago Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
CVE-2026-39373 low 2.5 15d ago Low: python-jwcrypto security update
CVE-2026-2728 low 2.5 16d ago LibreNMS: Cross-Site Scripting in ShowConfigController
CVE-2026-44638 low 2.5 2.5 20d ago libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointe…
CVE-2026-44970 low 2.5 20d ago dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
CVE-2026-44969 low 2.5 20d ago dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
CVE-2026-44348 low 2.5 2.5 20d ago PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFin…
CVE-2026-43529 low 2.5 2.5 29d ago OpenClaw: TOCTOU read in exec script preflight
CVE-2026-43864 low 2.5 2.5 1mo ago mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
CVE-2026-29051 low 2.5 1mo ago melange has Path Traversal via .PKGINFO in --persist-lint-results
CVE-2026-35377 low 2.5 1mo ago uutils coreutils has an Improper Input Validation Issue in its env Utility
CVE-2026-35381 low 2.5 1mo ago A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The im…
CVE-2026-35362 low 2.5 1mo ago The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to…
CVE-2026-35353 low 2.5 1mo ago The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them …
CVE-2026-35346 low 2.5 1mo ago The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 b…
CVE-2026-35361 low 2.5 1mo ago The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std…
CVE-2026-35367 low 2.5 1mo ago uutils coreutils has an Incorrect Permission Assignment for Critical Resource
CVE-2026-22746 low 2.5 1mo ago Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
CVE-2026-27769 low 2.5 2mo ago Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
CVE-2026-21388 low 2.5 2mo ago Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
CVE-2026-1340 unknown 2.5 2mo ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-34197 unknown 2.5 2mo ago Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-5420 low 2.5 2.5 2mo ago A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. …
CVE-2026-5310 low 2.5 2.5 2mo ago A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptograph…
CVE-2026-3055 unknown 2.5 2mo ago Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP lea…
CVE-2026-4823 low 2.5 2.5 2mo ago A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to inf…
CVE-2026-33168 low 2.5 2mo ago Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in…
CVE-2026-33167 low 2.5 2mo ago Rails has a possible XSS vulnerability in its Action Pack debug exceptions
CVE-2026-4541 low 2.5 2.5 2mo ago A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulat…
CVE-2026-4251 low 2.5 2.5 3mo ago A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets/assets/credentials.…
CVE-2026-4250 low 2.5 2.5 3mo ago A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account.json of the compone…
CVE-2026-4243 low 2.5 2.5 3mo ago A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component app.lanacion.activi…
CVE-2026-4242 low 2.5 2.5 3mo ago A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an unknown function of the file file app/babychakra/babychakra/Configuration.java of…
CVE-2026-4218 low 2.5 2.5 3mo ago A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/me/beta/utils/EngageBayUtils.java of the component aedes.me.beta. Performing a m…
CVE-2026-4217 low 2.5 2.5 3mo ago A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function of the file in ai/nreal/nebula/flutterPlugin/CloudStoragePlugin.java of the com…
CVE-2026-20127 unknown 2.5 3mo ago Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, re…
CVE-2026-2974 low 2.5 2.5 3mo ago A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The mani…
CVE-2026-2656 low 2.5 2.5 4mo ago A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use aft…
CVE-2026-2655 low 2.5 2.5 4mo ago A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::operator of the file include/chaiscript/chaiscript_defines.hpp. The manipulation res…
CVE-2026-2441 unknown 2.5 4mo ago Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-1731 unknown 2.5 4mo ago BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute oper…
CVE-2026-1281 unknown 2.5 4mo ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-24061 unknown 2.5 4mo ago GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2026-10529 low 2.4 2.4 1d ago A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unknown function of the file src/main/java/com/zhiliao/module/web/system/ScheduleJo…
CVE-2026-10514 low 2.4 2.4 1d ago A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The mani…
CVE-2026-10112 low 2.4 2.4 4d ago A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name leads to cross site s…
CVE-2026-49318 low 2.4 2.4 5d ago Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. T…
CVE-2026-49317 low 2.4 2.4 5d ago Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. T…
CVE-2026-9608 low 2.4 2.4 7d ago A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Executing a manipulation can le…
CVE-2026-9564 low 2.4 2.4 8d ago A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Perf…
CVE-2026-9377 low 2.4 2.4 10d ago A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName …
CVE-2026-9247 low 2.4 2.4 12d ago Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to admi…
CVE-2026-42188 low 2.4 2.4 22d ago Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser
CVE-2026-44658 low 2.4 2.4 23d ago Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same r…
CVE-2026-8262 low 2.4 2.4 23d ago A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scripting. The attack ma…
CVE-2026-8256 low 2.4 2.4 23d ago A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to cross site scriptin…
CVE-2026-8255 low 2.4 2.4 23d ago A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting. The attack c…
CVE-2026-8254 low 2.4 2.4 23d ago A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross si…
CVE-2026-8253 low 2.4 2.4 23d ago A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross …
CVE-2026-8221 low 2.4 2.4 24d ago A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible t…
CVE-2026-8220 low 2.4 2.4 24d ago A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting. The attack…
CVE-2026-8219 low 2.4 2.4 24d ago A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. The impacted element is an unknown function of the file /inventory/supplier-save. The manipulation leads to cross sit…
CVE-2026-8218 low 2.4 2.4 24d ago A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipulation can lead to cro…
CVE-2026-8136 low 2.4 2.4 26d ago A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation of the argument Name can lead…
CVE-2026-7297 low 2.4 2.4 1mo ago A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation…
CVE-2026-7296 low 2.4 2.4 1mo ago A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument…
CVE-2026-7295 low 2.4 2.4 1mo ago A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the …
CVE-2026-7294 low 2.4 2.4 1mo ago A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_settings. This manipulation o…
CVE-2026-7281 low 2.4 2.4 1mo ago A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier. Executing a manipulation …
CVE-2026-7269 low 2.4 2.4 1mo ago A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /index.php?page=product. Performing a manipulation of the argument ID …
CVE-2026-7090 low 2.4 2.4 1mo ago A vulnerability was detected in code-projects Chat System 1.0. This affects an unknown function of the file /admin/send_message.php of the component Chat Interface. The manipulation of the argument m…
CVE-2026-7016 low 2.4 2.4 1mo ago A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site…
CVE-2026-7015 low 2.4 2.4 1mo ago A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_emai…
CVE-2026-7014 low 2.4 2.4 1mo ago A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scrip…
CVE-2026-7013 low 2.4 2.4 1mo ago A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subje…
CVE-2026-7012 low 2.4 2.4 1mo ago A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting…
CVE-2026-7011 low 2.4 2.4 1mo ago A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a …
CVE-2026-7001 low 2.4 2.4 1mo ago A vulnerability was found in Datacom DM4100 1.3.6.1.4.1.3709. This affects an unknown part of the component Ethernet Configuration Page. Performing a manipulation of the argument Name results in cros…
CVE-2026-7000 low 2.4 2.4 1mo ago A vulnerability has been found in Datacom DM4100 1.3.6.1.4.1.3709. Affected by this issue is some unknown functionality of the component VLAN Page. Such manipulation of the argument VLAN Name leads t…
CVE-2026-6999 low 2.4 2.4 1mo ago A flaw has been found in BIVOCOM TR321 21.1.1.50. Affected by this vulnerability is an unknown functionality of the component Wireless Setting. This manipulation of the argument Network Name SSID cau…
CVE-2026-6998 low 2.4 2.4 1mo ago A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cr…
CVE-2026-6997 low 2.4 2.4 1mo ago A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner l…