CVEs from 2026
Total
14,084
critical
critical 1,231
high
high 4,631
medium
medium 4,442
low
low 483
% Critical
8.7%
% with KEV
0.4%
% with exploit
0.7%
Top vendors
Top products
- chrome 505
- firepower_threat_defense_software 300
- firepower_threat_defense 298
- gcp 239
- openclaw 172
- commerce 104
- commerce_b2b 89
- grafana 80
Top packages
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-44492 | unknown | — | — | 4d ago | axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) | |||
| CVE-2026-44490 | unknown | — | — | 4d ago | axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions | |||
| CVE-2026-44489 | unknown | — | — | 4d ago | Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix | |||
| CVE-2026-41237 | unknown | — | — | 4d ago | Froxlor has an incomplete fix for CVE-2026-30932 | |||
| CVE-2026-41236 | unknown | — | — | 4d ago | Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path | |||
| CVE-2026-41235 | unknown | — | — | 4d ago | Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement | |||
| CVE-2026-9509 | unknown | — | — | 5d ago | An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST reques… | |||
| CVE-2026-9508 | unknown | — | — | 5d ago | Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path w… | |||
| CVE-2026-8326 | unknown | — | — | 5d ago | Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component … | |||
| CVE-2026-45611 | unknown | — | — | 5d ago | Rejected reason: Further research determined the issue is not a vulnerability. | |||
| CVE-2026-45551 | unknown | — | — | 5d ago | Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings… | |||
| CVE-2026-45043 | unknown | — | — | 5d ago | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create se… | |||
| CVE-2026-49201 | unknown | — | — | 5d ago | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating pers… | |||
| CVE-2026-49200 | unknown | — | — | 5d ago | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized s… | |||
| CVE-2026-49199 | unknown | — | — | 5d ago | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. | |||
| CVE-2026-49198 | unknown | — | — | 5d ago | Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors. | |||
| CVE-2026-49197 | unknown | — | — | 5d ago | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails. | |||
| CVE-2026-49196 | unknown | — | — | 5d ago | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. | |||
| CVE-2026-49195 | unknown | — | — | 5d ago | Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands. | |||
| CVE-2026-49210 | unknown | — | — | 5d ago | symfony/ux-live-component XSS via attacker-controlled child component tag | |||
| CVE-2026-49208 | unknown | — | — | 5d ago | symfony/ux-live-component Format-less date LiveProps parsed with the permissive DateTime constructor | |||
| CVE-2026-49209 | unknown | — | — | 5d ago | symfony/ux-live-component Denial of service via unbounded batch action requests | |||
| CVE-2026-49215 | unknown | — | — | 5d ago | symfony/ux-live-component CSRF Protection Bypass: Accept Header is CORS-Safelisted | |||
| CVE-2026-49212 | unknown | — | — | 5d ago | symfony/ux-live-component LiveComponentHydrator HMAC checksum lacks component and slot binding | |||
| CVE-2026-49216 | unknown | — | — | 5d ago | symfony/ux-autocomplete XSS via unescaped AJAX response data | |||
| CVE-2026-49211 | unknown | — | — | 5d ago | symfony/ux-autocomplete Information exposure via unescaped LIKE wildcards in EntitySearchUtil | |||
| CVE-2026-8070 | unknown | — | — | 5d ago | Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical m… | |||
| CVE-2026-7480 | unknown | — | — | 5d ago | An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RP… | |||
| CVE-2026-42563 | unknown | — | — | 5d ago | Dulwich Vulnerable to Command Injection via Merge Driver Path | |||
| CVE-2026-42305 | unknown | — | — | 5d ago | Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows | |||
| CVE-2026-49299 | unknown | — | — | 5d ago | In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names e… | |||
| CVE-2026-45342 | unknown | — | — | 5d ago | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insecure Direct Object Reference vulnerability in the authorization policy layer that allows any authent… | |||
| CVE-2026-45343 | unknown | — | — | 5d ago | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScrip… | |||
| CVE-2026-47718 | unknown | — | — | 5d ago | FUXA provides guest and invalid-token access to protected read APIs in secure mode | |||
| CVE-2026-9039 | unknown | — | — | 5d ago | A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The se… | |||
| CVE-2026-9038 | unknown | — | — | 5d ago | A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed… | |||
| CVE-2026-9037 | unknown | — | — | 5d ago | A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic sign… | |||
| CVE-2026-33590 | unknown | — | — | 5d ago | Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with end… | |||
| CVE-2026-47144 | unknown | — | — | 5d ago | Shamefile has an arbitrary file read via shamefile.yaml in shame next | |||
| CVE-2026-47128 | unknown | — | — | 5d ago | nono: Sandbox escape on Linux via D-Bus: `systemd-run --user` | |||
| CVE-2026-47136 | unknown | — | — | 5d ago | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentic… | |||
| CVE-2026-46685 | unknown | — | — | 5d ago | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origi… | |||
| CVE-2026-45044 | unknown | — | — | 5d ago | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any… | |||
| CVE-2026-45042 | unknown | — | — | 5d ago | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing dest… | |||
| CVE-2026-45041 | unknown | — | — | 5d ago | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses i… | |||
| CVE-2026-45040 | unknown | — | — | 5d ago | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensit… | |||
| CVE-2026-46439 | unknown | — | — | 5d ago | compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) | |||
| CVE-2026-46405 | unknown | — | — | 5d ago | OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens | |||
| CVE-2026-46380 | unknown | — | — | 5d ago | compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem | |||
| CVE-2026-45297 | unknown | — | — | 5d ago | OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS… | |||
| CVE-2026-34126 | unknown | — | — | 5d ago | TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext witho… | |||
| CVE-2026-46358 | unknown | — | — | 5d ago | OpenBao's Inline Auth Incorrectly Redacted Headers | |||
| CVE-2026-46345 | unknown | — | — | 5d ago | compliance-trestle - jinja has an Arbitrary File Write via Path Traversal | |||
| CVE-2026-45808 | unknown | — | — | 5d ago | OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL | |||
| CVE-2026-45774 | unknown | — | — | 5d ago | compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal | |||
| CVE-2026-45287 | unknown | — | — | 5d ago | opentelemetry-go's Schema ParseFile leaks file descriptors on each parse | |||
| CVE-2026-8697 | unknown | — | — | 5d ago | Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web … | |||
| CVE-2026-6720 | unknown | — | — | 5d ago | When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embe… | |||
| CVE-2026-45261 | unknown | — | — | 5d ago | GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application. An a… | |||
| CVE-2026-41185 | unknown | — | — | 5d ago | When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, t… | |||
| CVE-2026-41184 | unknown | — | — | 5d ago | In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico d… | |||
| CVE-2026-41178 | unknown | — | — | 5d ago | opentelemetry-go's baggage parsing no longer caps raw header length | |||
| CVE-2026-22872 | unknown | — | — | 5d ago | Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets th… | |||
| CVE-2026-9828 | unknown | — | — | 6d ago | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precise… | |||
| CVE-2026-8990 | unknown | — | — | 6d ago | A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with applicat… | |||
| CVE-2026-8980 | unknown | — | — | 6d ago | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer a… | |||
| CVE-2026-8979 | unknown | — | — | 6d ago | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST re… | |||
| CVE-2026-42250 | unknown | — | — | 6d ago | bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corru… | |||
| CVE-2026-9813 | unknown | — | — | 6d ago | FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external… | |||
| CVE-2026-4377 | unknown | — | — | 6d ago | Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the defaul… | |||
| CVE-2026-47074 | unknown | — | — | 6d ago | Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Improper Validation. This vulnerability is associated wi… | |||
| CVE-2026-46241 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on registration failure Make sure to disable and free the interrupts in case controller registra… | |||
| CVE-2026-46239 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Fix runtime PM refcount leak in s_ctrl Three control cases (AUTOGAIN, EXPOSURE_AUTO, ANALOGUE_GAIN) directly … | |||
| CVE-2026-46236 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DMA restrictions The buffer for IO must not be part of the device structure because that violates th… | |||
| CVE-2026-46235 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: media: saa7164: add ioremap return checks and cleanups Add checks for ioremap return values in saa7164_dev_setup(). If ioremap fo… | |||
| CVE-2026-46234 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: vsock: fix buffer size clamping order In vsock_update_buffer_size(), the buffer size was being clamped to the maximum first, and … | |||
| CVE-2026-46233 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non-released claims When batadv_bla_purge_claims() goes through the list of claims, it is only traver… | |||
| CVE-2026-46231 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: put backbone reference on failed claim hash insert When batadv_bla_add_claim() fails to insert a new claim into … | |||
| CVE-2026-46229 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure KFD VRAM allocations set AMDGPU_GEM_CREATE_VRAM_WIPE_ON_RELEA… | |||
| CVE-2026-46228 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime ti… | |||
| CVE-2026-46226 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: spi: fsl: fix controller deregistration Make sure to deregister the controller before releasing underlying resources like DMA dur… | |||
| CVE-2026-46225 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: spi: rspi: fix controller deregistration Make sure to deregister the controller before releasing underlying resources like DMA du… | |||
| CVE-2026-46224 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure When drm_gpuvm_resv_object_alloc() fails, the pre-allocated st… | |||
| CVE-2026-46223 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: cgroup: Defer css percpu_ref kill on rmdir until cgroup is depopulated A chain of commits going back to v7.0 reworked rmdir to sa… | |||
| CVE-2026-46222 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: Add missing MUST_CONNECT flag to pads The pads missed checks for connected devices which may a null deref… | |||
| CVE-2026-46221 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: EDAC/versalnet: Fix device name memory leak The device name allocated via kzalloc() in init_one_mc() is assigned to dev->init_nam… | |||
| CVE-2026-46220 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission sdma_v4_0_ring_emit_fence() contains two BUG_ON(addr & 0x3) asser… | |||
| CVE-2026-46219 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on unbind The state machine work is scheduled by the interrupt handler and therefore needs to be… | |||
| CVE-2026-46217 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Avoid overflow on msg bound check As pointed out by SDL, the previous condition may be vulnerable to overflow. … | |||
| CVE-2026-46216 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() When media GT is disabled via configfs, there is no all… | |||
| CVE-2026-46214 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix accept queue count leak on transport mismatch virtio_transport_recv_listen() calls sk_acceptq_added() before vs… | |||
| CVE-2026-46213 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix UAF in inactivity-timer cleanup path Commit 38224c472a03 ("HID: appletb-kbd: fix slab use-after-free bug in… | |||
| CVE-2026-46211 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() msm_ioctl_gem_info_get_metadata() always returns 0 regardles… | |||
| CVE-2026-46207 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix empty payload in tap skb for non-linear buffers For non-linear skbs, virtio_transport_build_skb() goes through … | |||
| CVE-2026-46203 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on unbind Make sure that the controller is runtime resumed before disabling it during … | |||
| CVE-2026-46202 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: run inactivity autodim from workqueues The autodim code in hid-appletb-kbd takes backlight_device->ops_lock via… | |||
| CVE-2026-46200 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix controller deregistration Make sure to deregister the controller before disabling and releasing underlying reso… | |||
| CVE-2026-46196 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() When a tracepoint goes through the 0 -> 1 transition… | |||
| CVE-2026-46194 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix node_cnt race between extent node destroy and writeback f2fs_destroy_extent_node() does not set FI_NO_EXTENT before cle… | |||
| CVE-2026-46193 | unknown | — | — | 6d ago | In the Linux kernel, the following vulnerability has been resolved: xfrm: ah: account for ESN high bits in async callbacks AH allocates its temporary auth/ICV layout differently when ESN is enabled… |