Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26379
Total
1954
Critical
7969
High
8218
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44477 | UNKNOWN | — | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection … | May 28, 2026 |
| CVE-2026-44466 | HIGH | 8.6 | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary … | May 28, 2026 |
| CVE-2026-44465 | HIGH | 8.6 | Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the … | May 28, 2026 |
| CVE-2026-44463 | HIGH | 8.6 | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking … | May 28, 2026 |
| CVE-2026-44462 | MEDIUM | 6.4 | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command … | May 28, 2026 |
| CVE-2026-44461 | HIGH | 8.6 | Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but … | May 28, 2026 |
| CVE-2026-41185 | UNKNOWN | — | When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to … | May 28, 2026 |
| CVE-2026-41184 | UNKNOWN | — | In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the … | May 28, 2026 |
| CVE-2026-41160 | MEDIUM | 4.3 | EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users … | May 28, 2026 |
| CVE-2026-41141 | MEDIUM | 6.5 | EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter and resolves the owning entity … | May 28, 2026 |
| CVE-2026-38707 | CRITICAL | 9.8 | A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, … | May 28, 2026 |
| CVE-2026-38704 | CRITICAL | 9.8 | A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, … | May 28, 2026 |
| CVE-2026-38703 | CRITICAL | 9.8 | A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, … | May 28, 2026 |
| CVE-2026-38702 | CRITICAL | 9.8 | A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, … | May 28, 2026 |
| CVE-2026-24444 | CRITICAL | 9.8 | SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that … | May 28, 2026 |
| CVE-2026-48735 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to … | May 28, 2026 |
| CVE-2026-48526 | HIGH | 7.4 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and … | May 28, 2026 |
| CVE-2026-48525 | MEDIUM | 5.3 | PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC … | May 28, 2026 |
| CVE-2026-48524 | LOW | 3.7 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT … | May 28, 2026 |
| CVE-2026-48523 | MEDIUM | 5.4 | PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are … | May 28, 2026 |
| CVE-2026-48522 | MEDIUM | 4.2 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default … | May 28, 2026 |
| CVE-2026-48156 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to … | May 28, 2026 |
| CVE-2026-48155 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to … | May 28, 2026 |
| CVE-2026-47762 | HIGH | 8.7 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows … | May 28, 2026 |
| CVE-2026-47761 | HIGH | 8.7 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers … | May 28, 2026 |