Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26398
Total
1955
Critical
7975
High
8226
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-9082 | MEDIUM | 6.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: … | May 20, 2026 |
| CVE-2026-47099 | MEDIUM | 6.1 | TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted … | May 20, 2026 |
| CVE-2026-45444 | CRITICAL | 10.0 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards … | May 20, 2026 |
| CVE-2026-39850 | HIGH | 7.4 | Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local … | May 20, 2026 |
| CVE-2026-39405 | UNKNOWN | — | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing … | May 20, 2026 |
| CVE-2026-39352 | UNKNOWN | — | Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue … | May 20, 2026 |
| CVE-2026-39311 | MEDIUM | 6.8 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw … | May 20, 2026 |
| CVE-2026-39310 | HIGH | 8.6 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in … | May 20, 2026 |
| CVE-2026-35016 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35015 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35014 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35013 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values … | May 20, 2026 |
| CVE-2026-35012 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35011 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35010 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35009 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35008 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-35007 | MEDIUM | 4.6 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … | May 20, 2026 |
| CVE-2026-33137 | UNKNOWN | — | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In … | May 20, 2026 |
| CVE-2026-2813 | MEDIUM | 4.7 | ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, … | May 20, 2026 |
| CVE-2026-2812 | MEDIUM | 5.3 | ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to … | May 20, 2026 |
| CVE-2026-26028 | MEDIUM | 6.1 | CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute … | May 20, 2026 |
| CVE-2026-24218 | HIGH | 8.1 | NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be … | May 20, 2026 |
| CVE-2026-24217 | HIGH | 8.8 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of … | May 20, 2026 |
| CVE-2026-24216 | HIGH | 7.8 | NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead … | May 20, 2026 |