Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 417 CVEs
CVE-2026-7555 HIGH - 7.3

A vulnerability was identified in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/login.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

Published: May 01, 2026
Source: NVD
CVE-2026-41421 HIGH - 8.8

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast la...

Vendor: siyuan-note
Product: siyuan
Published: Apr 24, 2026
Source: NVD
CVE-2026-1952 CRITICAL - 9.8

Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

Published: Apr 24, 2026
Source: NVD
CVE-2026-1951 CRITICAL - 9.8

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

Published: Apr 24, 2026
Source: NVD
CVE-2026-1950 CRITICAL - 9.8

Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.

Published: Apr 24, 2026
Source: NVD
CVE-2026-1949 CRITICAL - 9.8

Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.

Published: Apr 24, 2026
Source: NVD
CVE-2026-40922 MEDIUM - 5.4

SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTML sanitizer, but the sanitizer does not block iframe tags, and its URL-prefix blocklist does not effe...

Vendor: siyuan-note
Product: siyuan
Published: Apr 17, 2026
Source: NVD
CVE-2026-40322 CRITICAL - 9.0

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks...

Vendor: siyuan-note
Product: siyuan
Published: Apr 16, 2026
Source: NVD
CVE-2026-5496 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in that th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5495 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5494 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5493 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-25203 HIGH - 7.8

Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1.

Vendor: Samsung Electronics
Product: MagicINFO 9 Server
Published: Apr 10, 2026
Source: NVD
CVE-2026-40107 HIGH - 6.5

SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with src attributes survive Mermaid's internal DOMPurify and land in SVG <foreignObject> blocks. The SV...

Vendor: siyuan-note
Product: siyuan
Published: Apr 09, 2026
Source: NVD
CVE-2026-39846 CRITICAL - 9.0

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, crea...

Vendor: siyuan-note
Product: siyuan
Published: Apr 07, 2026
Source: NVD
CVE-2026-39367 MEDIUM - 5.4

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a video'...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decode...

Vendor: npm
Product: electron
Published: Apr 07, 2026
Source: GitHub
CVE-2026-34765 MEDIUM - 6.0

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing ...

Vendor: npm
Product: electron
Published: Apr 07, 2026
Source: GitHub

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain conditions...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34780 HIGH - 8.4

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the co...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub