CVEs from 2026

14,443 normalized CVEs published or assigned in this year.

Total
14,443
critical
critical 1,273
high
high 4,904
medium
medium 4,598
low
low 500
% Critical
8.8%
% with KEV
0.4%
% with exploit
0.7%

Top vendors

Top products

  • chrome 522
  • firepower_threat_defense_software 310
  • gcp 299
  • firepower_threat_defense 298
  • openclaw 172
  • commerce 104
  • netweaver_application_server_abap 102
  • commerce_b2b 89
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-8137 high 8.8 8.8 28d ago A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url l…
CVE-2026-42271 high 8.8 8.8 28d ago LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVE-2026-42203 high 8.8 8.8 28d ago LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-8112 high 8.8 8.8 29d ago A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the file src/kernel.ts. Performing a manipulation resul…
CVE-2026-32207 high 8.8 8.8 29d ago Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42215 high 8.8 8.8 29d ago GitPython has Command Injection via Git options bypass
CVE-2026-5786 high 8.8 8.8 29d ago An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
CVE-2026-30495 high 8.8 8.8 29d ago The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without requiring authentication. The device is con…
CVE-2026-6002 high 8.8 8.8 29d ago Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affec…
CVE-2026-5784 high 8.8 8.8 29d ago Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyD…
CVE-2026-3953 high 8.8 8.8 29d ago Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XS…
CVE-2026-6692 high 8.8 8.8 29d ago The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient fil…
CVE-2026-41143 high 8.8 8.8 29d ago YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
CVE-2026-41139 high 8.8 8.8 29d ago mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-41640 high 8.8 8.8 29d ago @nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading
CVE-2026-41142 high 8.8 8.8 29d ago OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3…
CVE-2026-42550 high 8.8 8.8 1mo ago Flight vulnerable to SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete
CVE-2026-42844 high 8.8 8.8 1mo ago Low-privileged Grav API users can create super-admin accounts via blueprint-upload
CVE-2026-44115 high 8.8 8.8 1mo ago OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell ex…
CVE-2026-44110 high 8.8 8.8 1mo ago OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
CVE-2026-43584 high 8.8 8.8 1mo ago OpenClaw: Exec environment denylist missed high-risk interpreter startup variables
CVE-2026-40076 high 8.8 8.8 1mo ago OpenMRS Module Upload Vulnerable to Path Traversal (Zip Slip)
CVE-2026-8016 high 8.8 8.8 1mo ago Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-8002 high 8.8 8.8 1mo ago Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-8000 high 8.8 8.8 1mo ago Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium se…
CVE-2026-7995 high 8.8 8.8 1mo ago Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Mediu…
CVE-2026-7992 high 8.8 8.8 1mo ago Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute…
CVE-2026-7991 high 8.8 8.8 1mo ago Use after free in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…
CVE-2026-7988 high 8.8 8.8 1mo ago Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7987 high 8.8 8.8 1mo ago Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7984 high 8.8 8.8 1mo ago Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML …
CVE-2026-7980 high 8.8 8.8 1mo ago Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7974 high 8.8 8.8 1mo ago Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7973 high 8.8 8.8 1mo ago Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Med…
CVE-2026-7957 high 8.8 8.8 1mo ago Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a cr…
CVE-2026-7951 high 8.8 8.8 1mo ago Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7940 high 8.8 8.8 1mo ago Use after free in V8 in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome …
CVE-2026-7938 high 8.8 8.8 1mo ago Use after free in CSS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7930 high 8.8 8.8 1mo ago Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security sev…
CVE-2026-7928 high 8.8 8.8 1mo ago Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: …
CVE-2026-7927 high 8.8 8.8 1mo ago Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7926 high 8.8 8.8 1mo ago Use after free in PresentationAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi…
CVE-2026-7921 high 8.8 8.8 1mo ago Use after free in Passwords in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7907 high 8.8 8.8 1mo ago Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7906 high 8.8 8.8 1mo ago Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7903 high 8.8 8.8 1mo ago Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:…
CVE-2026-7902 high 8.8 8.8 1mo ago Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi…
CVE-2026-7901 high 8.8 8.8 1mo ago Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7899 high 8.8 8.8 1mo ago Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…
CVE-2026-7898 high 8.8 8.8 1mo ago Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
CVE-2026-7896 high 8.8 8.8 1mo ago Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-41938 high 8.8 8.8 1mo ago Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restricti…
CVE-2026-41934 high 8.8 8.8 1mo ago Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated users to execute arbitrary code through ins…
CVE-2026-7875 high 8.8 8.8 1mo ago NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container …
CVE-2026-42503 high 8.8 8.8 1mo ago gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopl…
CVE-2026-29080 high 8.8 8.8 1mo ago Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
CVE-2026-20034 high 8.8 8.8 1mo ago A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is…
CVE-2026-29090 high 8.8 8.8 1mo ago Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
CVE-2026-43283 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle dma_free_coherent() in error path takes priv->rx_buf.alloc_len as the d…
CVE-2026-43249 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against concurrent calls The xenwatch thread can race with other back-end change notification…
CVE-2026-43239 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in ->query_interfaces() It was possible for two query interface works to be concurrently trying to upd…
CVE-2026-43232 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fs…
CVE-2026-43215 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the se…
CVE-2026-43187 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: xfs: delete attr leaf freemap entries when empty Back in commit 2a2b5932db6758 ("xfs: fix attr leaf header freemap.size underflow…
CVE-2026-43176 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate release report content before using for RTL8922DE The commit 957eda596c76 ("wifi: rtw89: pci: validate…
CVE-2026-43172 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then us…
CVE-2026-43158 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: xfs: fix freemap adjustments when adding xattrs to leaf blocks xfs/592 and xfs/794 both trip this assertion in the leaf block fre…
CVE-2026-43113 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb() uses the firmware completion ID directly to ind…
CVE-2026-43112 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a str…
CVE-2026-43110 high 8.8 8.8 1mo ago In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF events brcmf_fweh_handle_if_event() validates the firmware-provided interface index…
CVE-2026-7841 high 8.8 8.8 1mo ago A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server b…
CVE-2026-42843 high 8.8 8.8 1mo ago Grav API Privilege Escalation to Super Admin
CVE-2026-40068 high 8.8 8.8 1mo ago Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
CVE-2026-39849 high 8.8 8.8 1mo ago Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline charac…
CVE-2026-42266 high 8.8 8.8 1mo ago JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
CVE-2026-34464 high 8.8 8.8 1mo ago Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fix…
CVE-2026-34459 high 8.8 8.8 1mo ago Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilit…
CVE-2026-34458 high 8.8 8.8 1mo ago Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration re…
CVE-2026-33324 high 8.8 8.8 1mo ago SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided que…
CVE-2026-25589 high 8.8 8.8 1mo ago RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTOR…
CVE-2026-25588 high 8.8 8.8 1mo ago RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE comma…
CVE-2026-25243 high 8.8 8.8 1mo ago RHSA-2026:23229: redis security update (Important)
CVE-2026-23479 high 8.8 8.8 1mo ago Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blo…
CVE-2026-35397 high 8.8 8.8 1mo ago Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_d…
CVE-2026-31196 high 8.8 8.8 1mo ago The traceroute diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing aut…
CVE-2026-31195 high 8.8 8.8 1mo ago The ping diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing authentic…
CVE-2026-6261 high 8.8 8.8 1mo ago The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled…
CVE-2026-43571 high 8.8 8.8 1mo ago OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
CVE-2026-43569 high 8.8 8.8 1mo ago OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins
CVE-2026-43531 high 8.8 8.8 1mo ago OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
CVE-2026-43530 high 8.8 8.8 1mo ago OpenClaw: busybox and toybox applet execution weakened exec approval binding
CVE-2026-42435 high 8.8 8.8 1mo ago OpenClaw: Shell-wrapper detection missed env-argv assignment injection forms
CVE-2026-42434 high 8.8 8.8 1mo ago OpenClaw: Sandboxed agents could escape exec routing via host=node override
CVE-2026-42606 high 8.8 8.8 1mo ago AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass
CVE-2026-42605 high 8.8 8.8 1mo ago AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload
CVE-2026-42237 high 8.8 8.8 1mo ago n8n has SQL Injection in Snowflake and MySQL Nodes
CVE-2026-42234 high 8.8 8.8 1mo ago n8n has a Python Task Runner Sandbox Escape Vulnerability
CVE-2026-42232 high 8.8 8.8 1mo ago n8n has XML Node Prototype Pollution that to RCE
CVE-2026-42231 high 8.8 8.8 1mo ago n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
CVE-2026-42229 high 8.8 8.8 1mo ago n8n has SQL Injection in SeaTable Node