Total CVEs

119,913

Critical Severity

1,691

High Severity

5,751

Last 7 Days

1,589
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1 - 20 of 16,318 CVEs
CVE-2026-5249 LOW - 3.5

A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attac...

Published: Apr 01, 2026
Source: NVD
CVE-2026-4947 HIGH - 7.1

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leadi...

Published: Apr 01, 2026
Source: NVD

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Service,Observability Collector,Recording Service,Queueing Service,Cloud Discovery Service) allows Serialized Data External Linking, Data Serializat...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3831 MEDIUM - 4.3

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Cont...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3780 HIGH - 7.3

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the l...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3779 HIGH - 7.8

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.

Published: Apr 01, 2026
Source: NVD
CVE-2026-3778 MEDIUM - 6.2

The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack ex...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3777 MEDIUM - 5.5

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3776 MEDIUM - 5.5

The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a cra...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3775 HIGH - 7.8

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writ...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3774 MEDIUM - 4.7

The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redact...

Published: Apr 01, 2026
Source: NVD
CVE-2026-5248 MEDIUM - 6.3

A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object attributes. The attack may be ...

Published: Apr 01, 2026
Source: NVD
CVE-2026-35057 MEDIUM - 6.4

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2026-35056 HIGH - 8.8

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2026-35055 MEDIUM - 6.1

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2026-35054 MEDIUM - 6.4

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.

Published: Apr 01, 2026
Source: NVD
CVE-2025-71282 HIGH - 7.5

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2025-71281 HIGH - 8.8

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks and variable method calls in templates, potentially allowing unauthorized method invocations.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2025-71280 MEDIUM - 6.2

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sensitive user information to other local users.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD