Total CVEs

125,843

Critical Severity

2,274

High Severity

7,870

Last 7 Days

1,169
Quick preset (or use dates below)
Clear Filters
Showing 181 - 200 of 7,870 CVEs
CVE-2025-67223 HIGH - 7.5

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7272 HIGH - 7.3

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lea...

Published: Apr 28, 2026
Source: NVD
CVE-2026-5944 HIGH - 8.2

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated...

Published: Apr 28, 2026
Source: NVD
CVE-2026-5435 HIGH - 7.3

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Published: Apr 28, 2026
Source: NVD
CVE-2026-3323 HIGH - 7.5

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7279 HIGH - 7.8

AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specific directory, resulting in arbitrary code execution with system privileges when the system loads the DLL.

Published: Apr 28, 2026
Source: NVD
CVE-2026-41636 HIGH - 7.5

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41605 HIGH - 7.3

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41604 HIGH - 8.2

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41603 HIGH - 7.4

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41602 HIGH - 7.5

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2025-48431 HIGH - 7.5

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift serve...

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-7247 HIGH - 7.2

A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The ex...

Vendor: dlink
Product: di-8100_firmware
Published: Apr 28, 2026
Source: NVD
CVE-2026-40978 HIGH - 8.8

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

Vendor: Spring
Product: Spring AI
Published: Apr 28, 2026
Source: NVD
CVE-2026-7237 HIGH - 7.3

A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold-mcp/src/server/index.ts of the component write-to-file Tool. The manipulation of the argument file_path results in path traversal. The attack may be l...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7234 HIGH - 7.3

A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit h...

Published: Apr 28, 2026
Source: NVD
CVE-2026-40967 HIGH - 8.6

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Affected versions: Spring AI: 1.0.0 -...

Vendor: Spring
Product: Spring AI
Published: Apr 28, 2026
Source: NVD
CVE-2026-7228 HIGH - 7.3

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has b...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7227 HIGH - 7.3

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login. The manipulation of the argument e-mail results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7226 HIGH - 7.3

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/ajax.php?action=login2. The manipulation of the argument e-mail leads to sql injection. Remote exploitation of the attack is possible. The exploit has ...

Published: Apr 28, 2026
Source: NVD