2026 · HIGH + CRITICAL · CVE Project mirror
Recent CVEs
Search 2026 HIGH and CRITICAL vulnerabilities ingested from the CVE Project V5 mirror. Refreshed every 5 minutes.
2,151 critical7,899 highLast ingest 2m ago@d61c1f3
100 most recent · without fix
CVE
Title / Vendor
Fix
CVSS
Severity
- CVE-2026-101792026-05-31TRENDnet TEW-432BRP formSetWlanEncrypt stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101652026-05-31Edimax BR-6478AC POST Request formWanTcpipSetup stack-based overflowEdimax / BR-6478ACNo fix8.7v4.0HIGH
- CVE-2026-101642026-05-31Edimax BR-6478AC POST Request formUSBFolder buffer overflowEdimax / BR-6478ACNo fix8.7v4.0HIGH
- CVE-2026-101632026-05-31Edimax BR-6478AC POST Request formUSBAccount buffer overflowEdimax / BR-6478ACNo fix8.7v4.0HIGH
- CVE-2026-101622026-05-31TRENDnet TEW-432BRP formSetPassword stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101612026-05-31TRENDnet TEW-432BRP formResetStatistic stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101602026-05-31TRENDnet TEW-432BRP formSetEnableWizard stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101592026-05-31TRENDnet TEW-432BRP formSysLog stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101582026-05-31TRENDnet TEW-432BRP formPortFw stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101262026-05-30Edimax BR-6478AC POST Request formQoS buffer overflowEdimax / BR-6478ACNo fix8.7v4.0HIGH
- CVE-2026-101252026-05-30Edimax BR-6478AC POST Request formPPPoESetup stack-based overflowEdimax / BR-6478ACNo fix8.7v4.0HIGH
- CVE-2026-101242026-05-30Shibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflowShibby / TomatoNo fix8.7v4.0HIGH
- CVE-2026-101232026-05-30TRENDnet TEW-432BRP formSetDomainFilter stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101222026-05-30TRENDnet TEW-432BRP formSetProtocolFilter stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101212026-05-30TRENDnet TEW-432BRP formSetUrlFilter stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101202026-05-30TRENDnet TEW-432BRP formSetFirewallRule stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-101192026-05-30TRENDnet TEW-432BRP formSetMACFilter stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-74592026-05-30Simple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction Endpointeskapism / Simple History – Track, Log, and Audit WordPress ChangesNo fix7.5v3.1HIGH
- CVE-2026-74652026-05-30Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributesbrainstormforce / Spectra Gutenberg Blocks – Website Builder for the Block EditorNo fix8.8v3.1HIGH
- CVE-2026-97572026-05-30GEO my WP <= 4.5.5 - Unauthenticated SQL Injection via 'swlatlng' / 'nelatlng' Parametersninjew / GEO my WPNo fix7.5v3.1HIGH
- CVE-2026-463852026-05-29iskorotkov/avro: CPU Exhaustion in Avro Decoderiskorotkov / avroNo fix8.7v4.0HIGH
- CVE-2026-463842026-05-29iskorotkov/avro: Integer Overflow in Avro Decoderiskorotkov / avroNo fix8.7v4.0HIGH
- CVE-2026-471232026-05-29FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Pathfreescout-help-desk / freescoutNo fix7.5v3.1HIGH
- CVE-2026-457002026-05-29Heap-buffer-overflow write in planar bitmap decoderFreeRDP / FreeRDPNo fix7.7v4.0HIGH
- CVE-2026-444202026-05-29FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPSFreeRDP / FreeRDPNo fix8.8v3.1HIGH
- CVE-2026-444222026-05-29FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusionFreeRDP / FreeRDPNo fix7.5v3.1HIGH
- CVE-2026-444212026-05-29FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle validation bypassFreeRDP / FreeRDPNo fix8.8v3.1HIGH
- CVE-2026-442852026-05-29FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview APIlabring / FastGPTNo fix7.7v3.1HIGH
- CVE-2026-453722026-05-29cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionyhirose / cpp-httplibNo fix9.9v3.1CRITICAL
- CVE-2026-465272026-05-29cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crashyhirose / cpp-httplibNo fix8.7v4.0HIGH
- CVE-2026-472662026-05-29Formie: Unauthenticated front-end submission editing can overwrite existing submissionsverbb / formieNo fix8.7v4.0HIGH
- CVE-2026-456972026-05-29Formie: Pre-authenticated server-side template injection in Hidden fieldsverbb / formieNo fix9.8v3.1CRITICAL
- CVE-2026-90512026-05-29Authentication Bypass Vulnerability in NI SystemLink EnterpriseNI / SystemLink EnterpriseNo fix9.3v4.0CRITICAL
- CVE-2026-477402026-05-29Shopper: Authorization bypass in multiple Livewire admin componentsshopperlabs / shopperNo fix8.1v3.1HIGH
- CVE-2026-477442026-05-29Shopper: Authorization bypass and RBAC privilege escalation in team settingsshopperlabs / shopperNo fix9.9v3.1CRITICAL
- CVE-2026-446502026-05-29SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')SillyTavern / SillyTavernNo fix9.1v3.1CRITICAL
- CVE-2026-446482026-05-29SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeoverSillyTavern / SillyTavernNo fix7.5v3.1HIGH
- CVE-2026-446492026-05-29SillyTavern: Authentication Bypass via SSO Header InjectionSillyTavern / SillyTavernNo fix9.8v3.1CRITICAL
- CVE-2026-463722026-05-29SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrlSillyTavern / SillyTavernNo fix8.5v3.1HIGH
- CVE-2026-456682026-05-29Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)TriliumNext / TriliumNo fix9.3v4.0CRITICAL
- CVE-2026-446972026-05-29Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payloadklever-io / klever-goNo fix8.6v3.1HIGH
- CVE-2026-77862026-05-29Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Use of Hard-coded CredentialsJinan USR IOT Technology Limited (PUSR) / USR-W610 RS232/485 to Wi-Fi/Ethernet ConverterNo fix9.8v3.1CRITICAL
- CVE-2026-456252026-05-29Arcane: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configsgetarcaneapp / arcaneNo fix9.9v3.1CRITICAL
- CVE-2026-456272026-05-29Arcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-images/logo enables admin account takeovergetarcaneapp / arcaneNo fix8.2v3.1HIGH
- CVE-2026-471252026-05-29Arcane: Missing admin authorization on global variables endpointgetarcaneapp / arcaneNo fix8.8v3.1HIGH
- CVE-2026-471792026-05-29Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcanegetarcaneapp / arcaneNo fix7.7v3.1HIGH
- CVE-2026-101082026-05-29xiaomusic 0.5.7 Path Traversal via GET /music endpointhanxi / xiaomusicNo fix8.7v4.0HIGH
- CVE-2026-101072026-05-29MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpointjxxghp / MoviePilotNo fix7.0v4.0HIGH
- CVE-2026-68242026-05-29CP Plus 8 Ch. Network Video Recorder Cross-site ScriptingCP Plus / CP-UNR-108F1 Hardware · CP Plus / CP-UNR-108F1 Web · CP Plus / CP-UNR-108F1 SystemNo fix8.4v3.1HIGH
- CVE-2026-456292026-05-29Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket EndpointDokploy / dokployNo fix9.9v3.1CRITICAL
- CVE-2026-456282026-05-29Dokploy: Command Injection via Unescaped Branch Fields in Deployment PipelineDokploy / dokployNo fix9.6v3.1CRITICAL
- CVE-2026-53862026-05-29KMW CCTV Security Cameras Unverified Password ChangeKMW / KM-IP521 · KMW / KM-IP421No fix9.1v3.1CRITICAL
- CVE-2026-101052026-05-29agno 2.6.5 SQL Injection via ClickHouse delete_by_metadata()agno-agi / agnoNo fix8.7v4.0HIGH
- CVE-2026-456302026-05-29Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo StatementDokploy / dokployNo fix9.0v3.1CRITICAL
- CVE-2026-456312026-05-29Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication SecretDokploy / dokployNo fix10.0v3.1CRITICAL
- CVE-2026-456322026-05-29Dokploy: Schedule Authorization Bypass Enables Host/Server Command ExecutionDokploy / dokployNo fix9.9v3.1CRITICAL
- CVE-2026-456332026-05-29Dokploy: Command Injection in /docker-container-logs EndpointDokploy / dokployNo fix9.9v3.1CRITICAL
- CVE-2026-456612026-05-29Dokploy: Remote Code Execution through Path TraversalDokploy / dokployNo fix9.9v3.1CRITICAL
- CVE-2026-456622026-05-29Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)Dokploy / dokployNo fix8.8v3.1HIGH
- CVE-2026-456632026-05-29Dokploy: Remote Code Execution via destinationPath in Container File UploadDokploy / dokployNo fix9.9v3.1CRITICAL
- CVE-2026-100692026-05-29Shibby Tomato miniupnpd resource consumptionShibby / TomatoNo fix8.7v4.0HIGH
- CVE-2026-100672026-05-29Shibby Tomato multimon.cgi sub_90F0 stack-based overflowShibby / TomatoNo fix8.7v4.0HIGH
- CVE-2026-100662026-05-29Shibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflowShibby / TomatoNo fix8.7v4.0HIGH
- CVE-2026-485012026-05-29GitHub CLI tokens leak via `gh attestation` commandscli / cliNo fix7.4v3.1HIGH
- CVE-2026-100652026-05-29Shibby Tomato tomatodata.cgi get_ups_field stack-based overflowShibby / TomatoNo fix8.7v4.0HIGH
- CVE-2026-100422026-05-29manga-image-translator RCE via Unsafe Pickle Deserialization in Share Modelzyddnys / manga-image-translatorNo fix9.2v4.0CRITICAL
- CVE-2026-42902026-05-29WP Travel Pro <= 10.6.0 - Missing Authorization to Unauthenticated Arbitrary User Deletion Including AdministratorsWPTravel / WP Travel ProNo fix9.1v3.1CRITICAL
- CVE-2026-100632026-05-29TRENDnet TEW-432BRP formWPS stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-456092026-05-29mcp-security: Unvalidated URL Fetching (SSRF)spring-ai-community / mcp-securityNo fix7.2v3.1HIGH
- CVE-2026-100622026-05-29TRENDnet TEW-432BRP formSetRoute stack-based overflowTRENDnet / TEW-432BRPNo fix8.7v4.0HIGH
- CVE-2026-465102026-05-29Prototype pollution in form-data-objectizer via bracket-notation form keyskaspernj / form-data-objectizerNo fix8.2v3.1HIGH
- CVE-2026-457072026-05-29n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incompleteczlonkowski / n8n-mcpNo fix8.1v3.1HIGH
- CVE-2026-446982026-05-29Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionhome-assistant / core · Home Assistant / Companion app (iOS) · Home Assistant / Companion app (Android)No fix8.3v3.1HIGH
- CVE-2026-456152026-05-29mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OER Payloadmouse07410 / asn1cNo fix8.2v3.1HIGH
- CVE-2026-455782026-05-29WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLWWBN / AVideoNo fix8.8v3.1HIGH
- CVE-2026-476962026-05-29WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpointWWBN / AVideoNo fix7.1v4.0HIGH
- CVE-2026-455552026-05-29Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagnostics Leads to Arbitrary Code ExecutionMarcelRoozekrans / roslyn-codelens-mcpNo fix7.8v3.1HIGH
- CVE-2026-442372026-05-29FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API ModuleFreePBX / security-reportingNo fix7.6v4.0HIGH
- CVE-2026-442382026-05-29FreePBX: Authenticated SQL Injection via ORDER BY in CDR ReportsFreePBX / security-reportingNo fix8.5v4.0HIGH
- CVE-2026-442392026-05-29FreePBX: Authenticated Local File Inclusion in Dashboard ModuleFreePBX / security-reportingNo fix7.6v4.0HIGH
- CVE-2026-463762026-05-29FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP InterfaceFreePBX / security-reportingNo fix9.3v4.0CRITICAL
- CVE-2026-100732026-05-29Interinfo|DreamMaker - Arbitrary File ReadInterinfo / DreamMakerNo fix8.7v4.0HIGH
- CVE-2026-100722026-05-29Interinfo|DreamMaker - Arbitrary File UploadInterinfo / DreamMakerNo fix8.6v4.0HIGH
- CVE-2026-100712026-05-29Interinfo|DreamMaker - Arbitrary File UploadInterinfo / DreamMakerNo fix9.3v4.0CRITICAL
- CVE-2026-485272026-05-29HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpointhaxtheweb / haxcms-nodejs · haxtheweb / haxcms-phpNo fix8.7v3.1HIGH
- CVE-2026-450432026-05-29RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Rootrustfs / rustfsNo fix9.3v4.0CRITICAL
- CVE-2026-453122026-05-29RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Executioninfiniflow / ragflowNo fix9.9v3.1CRITICAL
- CVE-2026-95092026-05-29Uncaught exception vulnerability in Suprema's BioStarSuprema / BioStar 2 (server)No fix8.7v4.0HIGH
- CVE-2026-429652026-05-29Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypasses destination validationRed Hat / Red Hat OpenShift Container Platform 4 · Red Hat / Red Hat OpenShift Container Platform 4No fix7.7v3.1HIGH
- CVE-2026-465792026-05-29Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontendRed Hat / Red Hat OpenShift Container Platform 4 · Red Hat / Red Hat OpenShift Container Platform 4No fix7.4v3.1HIGH
- CVE-2026-492012026-05-29Acer Wave 7 router: Hardcoded Cryptographic KeyAcer / Wave 7 routerNo fix10.0v4.0CRITICAL
- CVE-2026-492002026-05-29Acer Wave 7 router: Broken Access ControlAcer / Wave 7 routerNo fix10.0v4.0CRITICAL
- CVE-2026-491992026-05-29Predator Connect W6x: RCE via MQTTAcer / Predator Connect W6xNo fix10.0v4.0CRITICAL
- CVE-2026-491982026-05-29Predator Connect W6x: MQTT Broker Access ControlAcer / Predator Connect W6xNo fix8.3v4.0HIGH
- CVE-2026-491972026-05-29Predator Connect W6x: Improper AuthenticationAcer / Predator Connect W6xNo fix10.0v4.0CRITICAL
- CVE-2026-491962026-05-29Predator Connect W6x: Web Interface Command InjectionAcer / Predator Connect W6xNo fix8.6v4.0HIGH
- CVE-2026-491952026-05-29Predator Connect W6x: unauthenticated Debug ServiceAcer / Predator Connect W6xNo fix8.7v4.0HIGH
- CVE-2026-60752026-05-29Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action Formdglingren / Media Library AssistantNo fix8.1v3.1HIGH
- CVE-2026-36552026-05-29OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Authentication Bypass via Firebase OTP Verificationglboy / OTP Login With Phone Number, OTP VerificationNo fix9.8v3.1CRITICAL
- CVE-2026-94932026-05-29BankPro E-Service Technology|Service Center - Insecure Direct Object ReferenceBankPro E-Service Technology / Service CenterNo fix7.1v4.0HIGH