Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,210
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,981 - 2,000 of 22,583 CVEs

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

Published: Apr 22, 2026
Source: NVD

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

Published: Apr 22, 2026
Source: NVD

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

Published: Apr 22, 2026
Source: NVD

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

Published: Apr 22, 2026
Source: NVD

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

Published: Apr 22, 2026
Source: NVD

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

Published: Apr 22, 2026
Source: NVD
CVE-2026-6857 HIGH - 7.5

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6855 HIGH - 7.1

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unautho...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6848 MEDIUM - 5.4

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authent...

Published: Apr 22, 2026
Source: NVD
CVE-2026-33601 MEDIUM - 4.4

If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

Vendor: PowerDNS
Product: Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33600 MEDIUM - 4.4

An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

Vendor: PowerDNS
Product: Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33262 MEDIUM - 5.9

An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.

Vendor: PowerDNS
Product: Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33261 MEDIUM - 5.9

A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

Vendor: PowerDNS
Product: Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33260 MEDIUM - 5.3

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Vendor: PowerDNS
Product: Authoritative, DNSdist, Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33259 MEDIUM - 5.0

Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.

Vendor: PowerDNS
Product: Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33258 MEDIUM - 5.3

By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

Vendor: PowerDNS
Product: Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33257 MEDIUM - 5.3

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Vendor: PowerDNS
Product: Authoritative, DNSdist, Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-33256 MEDIUM - 5.3

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Vendor: PowerDNS
Product: Recursor
Published: Apr 22, 2026
Source: NVD
CVE-2026-1930 MEDIUM - 4.3

The Emailchef plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the page_options_ajax_disconnect() function in all versions up to, and including, 3.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and abo...

Published: Apr 22, 2026
Source: NVD
CVE-2026-1913 MEDIUM - 6.4

The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_link shortcode in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the 'prefix' attribute. This makes it possible...

Published: Apr 22, 2026
Source: NVD