Total CVEs

124,116

Critical Severity

2,092

High Severity

7,265

Last 7 Days

1,068
Quick preset (or use dates below)
Clear Filters
πŸ“† Custom Date Range: Apr 7, 2026 - Apr 7, 2026 Clear Custom Dates β†’
Showing 1 - 20 of 262 CVEs

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Apr 07, 2026
Source: NVD

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki vers...

Vendor: The Wikimedia Foundation
Product: Mediawiki - Score Extension
Published: Apr 07, 2026
Source: NVD

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: 1.43.7, 1.44.4, 1.45.2.

Vendor: The Wikimedia Foundation
Product: Mediawiki - CampaignEvents Extension
Published: Apr 07, 2026
Source: NVD

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exist...

Vendor: Ping Identity
Product: PingIDM
Published: Apr 07, 2026
Source: NVD
CVE-2026-4065 MEDIUM - 5.4

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (whi...

Published: Apr 07, 2026
Source: NVD

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.Β The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.4...

Vendor: The Wikimedia Foundation
Product: Mediawiki - CentralAuth Extension
Published: Apr 07, 2026
Source: NVD

Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions.This issue affects Mediawiki - GrowthExperiments Extension: 1.45.2, 1.44.4, 1.43...

Vendor: The Wikimedia Foundation
Product: Mediawiki - GrowthExperiments Extension
Published: Apr 07, 2026
Source: NVD

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for Medi...

Vendor: The Wikimedia Foundation
Product: Mediawiki - GlobalWatchlist Extension
Published: Apr 07, 2026
Source: NVD
CVE-2026-39847 CRITICAL - 9.1

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attacker can use ../ sequences (eg /__emmett__/../rsgi/handlers.py) to read arbi...

Vendor: emmett-framework
Product: emmett
Published: Apr 07, 2026
Source: NVD
CVE-2026-39846 CRITICAL - 9.0

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, crea...

Vendor: siyuan-note
Product: siyuan
Published: Apr 07, 2026
Source: NVD
CVE-2026-35568 HIGH - 5.7

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or n...

Vendor: modelcontextprotocol
Product: java-sdk
Published: Apr 07, 2026
Source: NVD
CVE-2026-35406 MEDIUM - 6.2

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.

Vendor: containers
Product: aardvark-dns
Published: Apr 07, 2026
Source: NVD

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which enti...

Vendor: randombit
Product: botan
Published: Apr 07, 2026
Source: NVD

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the c...

Vendor: randombit
Product: botan
Published: Apr 07, 2026
Source: NVD
CVE-2026-34371 MEDIUM - 6.3

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments using the default local file strategy, a malicious artifact filename containing traversal sequences (fo...

Vendor: danny-avila
Product: LibreChat
Published: Apr 07, 2026
Source: NVD
CVE-2026-34079 HIGH - 7.5

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the...

Vendor: flatpak
Product: flatpak
Published: Apr 07, 2026
Source: NVD

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to ...

Vendor: flatpak
Product: flatpak
Published: Apr 07, 2026
Source: NVD
CVE-2026-31790 HIGH - 7.5

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior. If an attacker ca...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-28390 HIGH - 7.5

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial ...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD