Total CVEs

125,574

Critical Severity

2,253

High Severity

7,771

Last 7 Days

1,121
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 221 - 240 of 21,979 CVEs
CVE-2026-7283 MEDIUM - 4.7

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expired. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7282 MEDIUM - 4.7

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is p...

Published: Apr 28, 2026
Source: NVD

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0....

Vendor: Spring
Product: Spring gRPC
Published: Apr 28, 2026
Source: NVD
CVE-2026-40968 MEDIUM - 4.2

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Sp...

Vendor: Spring
Product: Spring gRPC
Published: Apr 28, 2026
Source: NVD

GNU nano creates the user’s ~/.local directory with overly permissive permissions when the directory does not exist yet. On first use of features requiring Cross-Desktop Group (XDG) data storage, nano explicitly requests directory mode 0777, making the directory world‑writable in environments where ...

Vendor: GNU
Product: nano
Published: Apr 28, 2026
Source: NVD
CVE-2026-27760 HIGH - 8.1

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string conte...

Vendor: opencats
Product: OpenCATS
Published: Apr 28, 2026
Source: NVD
CVE-2025-67223 HIGH - 7.5

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7281 LOW - 2.4

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be performed from remote. The e...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7272 HIGH - 7.3

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lea...

Published: Apr 28, 2026
Source: NVD
CVE-2026-6706 MEDIUM - 6.5

Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.

Published: Apr 28, 2026
Source: NVD
CVE-2026-5944 HIGH - 8.2

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated...

Published: Apr 28, 2026
Source: NVD

mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path in the database to reference an attacker-controlled remote n...

Vendor: BinSoft
Product: mpGabinet
Published: Apr 28, 2026
Source: NVD

mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 ...

Vendor: BinSoft
Product: mpGabinet
Published: Apr 28, 2026
Source: NVD

mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running application instance connected to the backend server can extract database credentials from the application’s memory by inspecting ...

Vendor: BinSoft
Product: mpGabinet
Published: Apr 28, 2026
Source: NVD
CVE-2026-7309 MEDIUM - 4.3

A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulner...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7271 MEDIUM - 5.3

A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-agent-server. Performing a manipulation of the argument req.params results in path traversal. Remote ex...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7269 LOW - 2.4

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /index.php?page=product. Performing a manipulation of the argument ID results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been...

Published: Apr 28, 2026
Source: NVD

An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their privileges by sending an HTTP request with a manipulated 'identifier' field....

Published: Apr 28, 2026
Source: NVD

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authenticated user can access the data of other registered users simply by modifying the ID. Th...

Published: Apr 28, 2026
Source: NVD

An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the information of other registered users. Successful exploitation of this vulnerability allo...

Published: Apr 28, 2026
Source: NVD