CVEs from 2026

14,769 normalized CVEs published or assigned in this year.

Total
14,769
critical
critical 1,335
high
high 5,011
medium
medium 4,834
low
low 504
% Critical
9.0%
% with KEV
0.4%
% with exploit
0.7%

Top vendors

Top products

  • chrome 723
  • firepower_threat_defense_software 310
  • gcp 299
  • firepower_threat_defense 298
  • openclaw 172
  • commerce 104
  • netweaver_application_server_abap 102
  • commerce_b2b 89
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-42223 medium 6.5 6.5 1mo ago Nginx-UI Settings API Exposes Protected Secrets
CVE-2026-42220 medium 6.5 6.5 1mo ago Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback
CVE-2026-42069 medium 6.5 6.5 1mo ago Kirby CMS's read access to site, user and role information is not gated by permissions
CVE-2026-42228 medium 6.5 6.5 1mo ago n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
CVE-2026-42227 medium 6.5 6.5 1mo ago n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
CVE-2026-42092 medium 6.5 6.5 1mo ago titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscr…
CVE-2026-42091 medium 6.5 6.5 1mo ago goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
CVE-2026-37458 medium 6.5 6.5 1mo ago FRR vulnerabilities
CVE-2026-33523 medium 6.5 6.5 1mo ago Apache HTTP Server vulnerabilities
CVE-2026-20450 medium 6.5 6.5 1mo ago In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with…
CVE-2026-20449 medium 6.5 6.5 1mo ago In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with n…
CVE-2026-7714 medium 6.5 6.5 1mo ago A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This …
CVE-2026-42367 medium 6.5 6.5 1mo ago A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker …
CVE-2026-42256 medium 6.5 6.5 1mo ago net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-5337 medium 6.5 6.5 1mo ago During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability ex…
CVE-2026-7681 medium 6.5 6.5 1mo ago A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the file backend/webserver/api/datasets.py of the comp…
CVE-2026-7645 medium 6.5 6.5 1mo ago sublinear-time-solver has a Path Traversal Issue
CVE-2026-7633 medium 6.5 6.5 1mo ago A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to…
CVE-2026-6457 medium 6.5 6.5 1mo ago The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to, and including, 1.13.19 due to insufficient escapi…
CVE-2026-42474 medium 6.5 6.5 1mo ago MixPHP Framework has an SQL injection vulnerability via crafted `data` array
CVE-2026-42475 medium 6.5 6.5 1mo ago MixPHP Framework has an SQL injection vulnerability
CVE-2026-26461 medium 6.5 6.5 1mo ago A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request.
CVE-2026-23863 medium 6.5 6.5 1mo ago An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the a…
CVE-2026-43505 medium 6.5 6.5 1mo ago An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relayin…
CVE-2026-43504 medium 6.5 6.5 1mo ago An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of u…
CVE-2026-28909 medium 6.5 6.5 1mo ago Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
CVE-2026-1577 medium 6.5 6.5 1mo ago IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr…
CVE-2026-4502 medium 6.5 6.5 1mo ago IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot d…
CVE-2026-40950 medium 6.5 6.5 1mo ago CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and caus…
CVE-2026-3340 medium 6.5 6.5 1mo ago IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pote…
CVE-2026-28532 medium 6.5 6.5 1mo ago FRR vulnerabilities
CVE-2026-3345 medium 6.5 6.5 1mo ago IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../)…
CVE-2026-42137 medium 6.5 6.5 1mo ago Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
CVE-2026-40603 medium 6.5 6.5 1mo ago Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that return…
CVE-2026-35514 medium 6.5 6.5 1mo ago Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any …
CVE-2026-3833 medium 6.5 6.5 1mo ago GnuTLS vulnerabilities
CVE-2026-36759 medium 6.5 6.5 1mo ago A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
CVE-2026-7382 medium 6.5 6.5 1mo ago Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation.…
CVE-2026-41658 medium 6.5 6.5 1mo ago Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items
CVE-2026-41655 medium 6.5 6.5 1mo ago Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials
CVE-2026-7425 medium 6.5 6.5 1mo ago Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash…
CVE-2026-7423 medium 6.5 6.5 1mo ago Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing pi…
CVE-2026-7422 medium 6.5 6.5 1mo ago Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC ad…
CVE-2026-41499 medium 6.5 6.5 1mo ago Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exis…
CVE-2026-26206 medium 6.5 6.5 1mo ago Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security…
CVE-2026-38993 medium 6.5 6.5 1mo ago Cockpit is vulnerable to directory traversal
CVE-2026-42521 medium 6.5 6.5 1mo ago Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors
CVE-2026-22740 medium 6.5 6.5 1mo ago Spring Framework DoS with Multipart Temp Files in WebFlux
CVE-2026-42412 medium 6.5 6.5 1mo ago Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
CVE-2026-6238 medium 6.5 6.5 1mo ago The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing…
CVE-2026-42430 medium 6.5 6.5 1mo ago OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable
CVE-2026-42420 medium 6.5 6.5 1mo ago OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks
CVE-2026-41911 medium 6.5 6.5 1mo ago OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix)
CVE-2026-41408 medium 6.5 6.5 1mo ago OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk
CVE-2026-41388 medium 6.5 6.5 1mo ago OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config
CVE-2026-41385 medium 6.5 6.5 1mo ago OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get
CVE-2026-41376 medium 6.5 6.5 1mo ago OpenClaw: Matrix thread root and reply context bypass sender allowlist
CVE-2026-41375 medium 6.5 6.5 1mo ago OpenClaw: `/phone arm`/`/phone disarm` Bypasses `operator.admin` Scope Check for External Channels
CVE-2026-24204 medium 6.5 6.5 1mo ago NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.
CVE-2026-6706 medium 6.5 6.5 1mo ago Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. …
CVE-2026-41607 medium 6.5 6.5 1mo ago Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
CVE-2026-40980 medium 6.5 6.5 1mo ago Spring AI Vulnerable to OOM by attacker-controlled PDF
CVE-2026-41525 medium 6.5 6.5 1mo ago KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of …
CVE-2026-41370 medium 6.5 6.5 1mo ago OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can …
CVE-2026-41369 medium 6.5 6.5 1mo ago OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
CVE-2026-41368 medium 6.5 6.5 1mo ago OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using …
CVE-2026-41363 medium 6.5 6.5 1mo ago OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image
CVE-2026-41465 medium 6.5 6.5 1mo ago ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal seque…
CVE-2026-41081 medium 6.5 6.5 1mo ago Apache Storm's Improper Handling of TLS Client Authentication Failure Leads to Anonymous Principal Assignment
CVE-2026-42255 medium 6.5 6.5 1mo ago Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
CVE-2026-41481 medium 6.5 6.5 1mo ago LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
CVE-2026-6968 medium 6.5 6.5 1mo ago Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute…
CVE-2026-6967 medium 6.5 6.5 1mo ago awslabs/tough is Missing Delegated Metadata Validation
CVE-2026-6966 medium 6.5 6.5 1mo ago awslabs/tough Delegated Roles have a Signature Threshold Bypass
CVE-2026-41427 medium 6.5 6.5 1mo ago OAuth 2.1 Provider: Unprivileged users can register OAuth clients
CVE-2026-42041 medium 6.5 6.5 1mo ago Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
CVE-2026-42202 medium 6.5 6.5 1mo ago nova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fields
CVE-2026-5265 medium 6.5 6.5 1mo ago When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total leng…
CVE-2026-41340 medium 6.5 6.5 2mo ago OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-account trust into all named accounts. Attackers can exp…
CVE-2026-41334 medium 6.5 6.5 2mo ago OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. Attackers can exploit this by uploading oversized …
CVE-2026-41908 medium 6.5 6.5 2mo ago OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
CVE-2026-5926 medium 6.5 6.5 2mo ago IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Acce…
CVE-2026-41314 medium 6.5 6.5 2mo ago pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVE-2026-6355 medium 6.5 6.5 2mo ago A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to u…
CVE-2026-31192 medium 6.5 6.5 2mo ago Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted request.
CVE-2026-6834 medium 6.5 6.5 2mo ago The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method.
CVE-2026-6833 medium 6.5 6.5 2mo ago The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
CVE-2026-40924 medium 6.5 6.5 2mo ago Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
CVE-2026-41320 medium 6.5 6.5 2mo ago Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, al…
CVE-2026-40889 medium 6.5 6.5 2mo ago Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Ver…
CVE-2026-40888 medium 6.5 6.5 2mo ago Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting…
CVE-2026-40161 medium 6.5 6.5 2mo ago Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
CVE-2026-30452 medium 6.5 6.5 2mo ago Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher…
CVE-2026-25542 medium 6.5 6.5 2mo ago Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
CVE-2026-39396 medium 6.5 6.5 2mo ago OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-6588 medium 6.5 6.5 2mo ago A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API …
CVE-2026-6579 medium 6.5 6.5 2mo ago A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing a…
CVE-2026-6437 medium 6.5 6.5 2mo ago Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creati…
CVE-2026-40346 medium 6.5 6.5 2mo ago NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins
CVE-2026-40293 medium 6.5 6.5 2mo ago OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response