Total CVEs

126,186

Critical Severity

2,292

High Severity

7,951

Last 7 Days

1,205
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,081 - 2,100 of 22,591 CVEs
CVE-2026-6386 MEDIUM - 6.2

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3) interface. In particular, i...

Published: Apr 22, 2026
Source: NVD
CVE-2026-5398 HIGH - 8.4

The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end up containing a pointer to freed memory. A malicious process can abuse th...

Published: Apr 22, 2026
Source: NVD

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent reque...

Vendor: owntone
Product: owntone-server
Published: Apr 22, 2026
Source: NVD

OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the query= and filter= parameters for integer-mapped DAAP fields. Attackers can exploit in...

Vendor: owntone
Product: owntone-server
Published: Apr 22, 2026
Source: NVD

facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value starting with `i` or `I`. The process spins in user space and pegs one CPU core at ~100% instead of retur...

Vendor: boazsegev
Product: facil.io, iodine
Published: Apr 22, 2026
Source: NVD
CVE-2026-41145 HIGH - 8.2

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path allows any user who knows a valid access key to write arbitrary...

Vendor: minio
Product: minio
Published: Apr 22, 2026
Source: NVD
CVE-2026-40344 HIGH - 8.2

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-extract handler (`PutObjectExtractHandler`) allows any user who knows a valid access key to writ...

Vendor: minio
Product: minio
Published: Apr 22, 2026
Source: NVD
CVE-2026-41304 CRITICAL - 9.8

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed...

Vendor: WWBN
Product: AVideo
Published: Apr 22, 2026
Source: NVD

Fยด (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An attacker-crafted DataPacket with byteOffset=0x...

Vendor: nasa
Product: fprime
Published: Apr 22, 2026
Source: NVD
CVE-2026-41136 MEDIUM - 5.3

free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Conte...

Vendor: free5gc
Product: amf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41135 HIGH - 7.5

free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability in versions prior to 1.4.3 allows any unauthenticated attacker with network access to the PCF SBI interface to cause uncontrolled memory g...

Vendor: free5gc
Product: pcf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41133 HIGH - 8.8

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the dat...

Vendor: pyload
Product: pyload
Published: Apr 22, 2026
Source: NVD
CVE-2026-41131 MEDIUM - 5.0

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for ...

Vendor: openfga
Product: openfga
Published: Apr 22, 2026
Source: NVD

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default con...

Vendor: craftcms
Product: cms
Published: Apr 22, 2026
Source: NVD

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName>...

Vendor: craftcms
Product: cms
Published: Apr 22, 2026
Source: NVD

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it perform...

Vendor: craftcms
Product: cms
Published: Apr 22, 2026
Source: NVD
CVE-2026-41127 MEDIUM - 6.5

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.

Vendor: bigbluebutton
Product: bigbluebutton
Published: Apr 22, 2026
Source: NVD
CVE-2026-41126 MEDIUM - 4.3

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known worka...

Vendor: bigbluebutton
Product: bigbluebutton
Published: Apr 22, 2026
Source: NVD
CVE-2026-41064 CRITICAL - 9.3

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation regex `/^http/` accepts strings like `httpevi...

Vendor: WWBN
Product: AVideo
Published: Apr 22, 2026
Source: NVD
CVE-2026-41059 HIGH - 8.2

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patt...

Vendor: oauth2-proxy
Product: oauth2-proxy
Published: Apr 22, 2026
Source: NVD