Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26897
Total
1982
Critical
8080
High
8318
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5361 | MEDIUM | 6.4 | The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This … | May 14, 2026 |
| CVE-2026-5486 | MEDIUM | 6.5 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up … | May 14, 2026 |
| CVE-2026-46446 | HIGH | 7.1 | SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in … | May 14, 2026 |
| CVE-2026-46445 | HIGH | 7.1 | SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. | May 14, 2026 |
| CVE-2026-46419 | HIGH | 7.5 | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation. | May 14, 2026 |
| CVE-2026-44919 | MEDIUM | 4.3 | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. | May 14, 2026 |
| CVE-2026-41281 | MEDIUM | 4.8 | Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify communications … | May 14, 2026 |
| CVE-2026-8500 | CRITICAL | 9.8 | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The … | May 13, 2026 |
| CVE-2026-32991 | HIGH | 7.1 | Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account. | May 13, 2026 |
| CVE-2026-29206 | HIGH | 8.1 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled. | May 13, 2026 |
| CVE-2026-45158 | CRITICAL | 9.1 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, … | May 13, 2026 |
| CVE-2026-44478 | HIGH | 7.5 | hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and … | May 13, 2026 |
| CVE-2026-44471 | HIGH | 7.8 | gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, … | May 13, 2026 |
| CVE-2026-44448 | MEDIUM | 5.9 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing … | May 13, 2026 |
| CVE-2026-44447 | HIGH | 8.8 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, … | May 13, 2026 |
| CVE-2026-44446 | HIGH | 8.8 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially … | May 13, 2026 |
| CVE-2026-44445 | UNKNOWN | — | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference … | May 13, 2026 |
| CVE-2026-44442 | CRITICAL | 9.9 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to … | May 13, 2026 |
| CVE-2026-44441 | MEDIUM | 5.0 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to … | May 13, 2026 |
| CVE-2026-44440 | MEDIUM | 6.5 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted … | May 13, 2026 |
| CVE-2026-44439 | UNKNOWN | — | PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. … | May 13, 2026 |
| CVE-2026-44437 | UNKNOWN | — | The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the … | May 13, 2026 |
| CVE-2026-44426 | MEDIUM | 6.5 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — including the members list (user IDs, e-mails, roles), … | May 13, 2026 |
| CVE-2026-44425 | MEDIUM | 5.4 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property … | May 13, 2026 |
| CVE-2026-44424 | MEDIUM | 6.5 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever the caller is authenticated, without verifying that the … | May 13, 2026 |