Total CVEs

125,728

Critical Severity

2,261

High Severity

7,831

Last 7 Days

1,201
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 221 - 240 of 22,133 CVEs
CVE-2026-4019 MEDIUM - 5.3

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing...

Published: Apr 29, 2026
Source: NVD

This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keys...

Vendor: CDAC-Noida
Product: e-Sushrut, Hospital Management Information System (HMIS)
Published: Apr 29, 2026
Source: NVD

This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulating Base64-encoded parameters in the request URL to gain unauthorized access to sensitive information...

Vendor: CDAC-Noida
Product: e-Sushrut, Hospital Management Information System (HMIS)
Published: Apr 29, 2026
Source: NVD

This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vulnerability by manipulating encoded parameters in the request URL to gain unauthorized access to patient accounts on the targeted system.

Vendor: CDAC-Noida
Product: e-Sushrut, Hospital Management Information System (HMIS)
Published: Apr 29, 2026
Source: NVD

This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system.

Vendor: CDAC-Noida
Product: e-Sushrut, Hospital Management Information System (HMIS)
Published: Apr 29, 2026
Source: NVD

This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs. Successful exploitation of this vulnerability could allow an attacker to impersonate the target u...

Vendor: CDAC-Noida
Product: e-Sushrut, Hospital Management Information System (HMIS)
Published: Apr 29, 2026
Source: NVD

This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response. Successful exploitation of this vuln...

Vendor: CDAC-Noida
Product: e-Sushrut, Hospital Management Information System (HMIS)
Published: Apr 29, 2026
Source: NVD
CVE-2026-42412 MEDIUM - 6.5

Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.

Vendor: weDevs
Product: WP User Frontend
Published: Apr 29, 2026
Source: NVD

SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The vulnerability arises from inadequate validation and sanitisation of user input. Specifically, via a POST request, the “id_territorio” parameter, used im...

Published: Apr 29, 2026
Source: NVD
CVE-2025-10503 MEDIUM - 6.1

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerabilit...

Vendor: WSO2
Product: WSO2 Identity Server
Published: Apr 29, 2026
Source: NVD
CVE-2026-42377 HIGH - 7.3

Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.

Vendor: Brainstorm Force
Product: SureForms Pro
Published: Apr 29, 2026
Source: NVD
CVE-2026-35155 HIGH - 7.1

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.

Vendor: Dell
Product: iDRAC10
Published: Apr 29, 2026
Source: NVD

Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Apr 29, 2026
Source: NVD
CVE-2026-42615 HIGH - 7.2

GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

Vendor: GCHQ
Product: CyberChef
Published: Apr 29, 2026
Source: NVD
CVE-2026-23773 MEDIUM - 4.3

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

Vendor: Dell
Product: Disk Library for mainframe DLm8700, Disk Library for mainframe DLm2700
Published: Apr 29, 2026
Source: NVD
CVE-2026-40560 HIGH - 7.5

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must t...

Vendor: MIYAGAWA
Product: Starman
Published: Apr 29, 2026
Source: NVD
CVE-2026-41310 MEDIUM - 5.3

OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure

Vendor: nuget
Product: OpenTelemetry.Exporter.Zipkin
Published: Apr 28, 2026
Source: GitHub
CVE-2026-7363 HIGH - 8.8

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7361 HIGH - 8.8

Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7360 LOW - 3.1

Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Published: Apr 28, 2026
Source: NVD