Total CVEs

125,862

Critical Severity

2,275

High Severity

7,879

Last 7 Days

1,167
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 201 - 220 of 22,267 CVEs
CVE-2026-42353 HIGH - 8.2

i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters

Vendor: npm
Product: i18next-http-middleware
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42352 HIGH - 8.6

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

Vendor: pip
Product: pygeoapi
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42351 HIGH - 7.5

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

Vendor: pip
Product: pygeoapi
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7418 HIGH - 8.8

A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function strcpy of the file route/goform/NTP. Executing a manipulation of the argument Profile can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7417 HIGH - 7.3

A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of the argument media_paths results in server-side request forgery. The attack may be initiated remotely....

Published: Apr 29, 2026
Source: NVD
CVE-2026-7416 HIGH - 7.3

A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7410 MEDIUM - 6.3

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7409 MEDIUM - 4.7

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

Published: Apr 29, 2026
Source: NVD
CVE-2026-41671 MEDIUM - 6.8

Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41670 HIGH - 8.2

Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41669 HIGH - 8.2

Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub

Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41662 MEDIUM - 5.2

Admidio Missing Minimum Administrator Check in Role Membership Removal

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41661 MEDIUM - 6.1

Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41660 HIGH - 7.1

Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub

Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41658 MEDIUM - 6.5

Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41657 MEDIUM - 4.9

Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41656 MEDIUM - 4.5

Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41655 MEDIUM - 6.5

Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub