Total CVEs

126,186

Critical Severity

2,292

High Severity

7,951

Last 7 Days

1,205
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,401 - 2,420 of 22,591 CVEs
CVE-2026-39467 HIGH - 7.2

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.

Vendor: MetaSlider
Product: Responsive Slider by MetaSlider
Published: Apr 21, 2026
Source: NVD

Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vulnerability is caused by inadequate validation of user-supplied input. An attacker can exploit this vulnerability by sending malicious requests. If the vulnerability is succes...

Vendor: Zervit
Product: portable HTTP/Web server
Published: Apr 21, 2026
Source: NVD
CVE-2026-6712 MEDIUM - 4.4

The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...

Published: Apr 21, 2026
Source: NVD
CVE-2026-6711 MEDIUM - 6.1

The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.6. This is due to the use of filter_input() without a sanitization filter and insufficient output escaping. This makes it possible for...

Published: Apr 21, 2026
Source: NVD
CVE-2026-6703 MEDIUM - 4.3

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authentica...

Published: Apr 21, 2026
Source: NVD
CVE-2026-31370 MEDIUM - 6.3

Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Vendor: Honor
Product: Honor E
Published: Apr 21, 2026
Source: NVD

PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability

Vendor: Honor
Product: PcManager
Published: Apr 21, 2026
Source: NVD
CVE-2026-31368 HIGH - 7.8

AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

Vendor: Honor
Product: AIAssistant
Published: Apr 21, 2026
Source: NVD
CVE-2026-5965 CRITICAL - 9.8

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Published: Apr 21, 2026
Source: NVD
CVE-2026-6675 MEDIUM - 5.3

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address suppli...

Published: Apr 21, 2026
Source: NVD
CVE-2026-6674 MEDIUM - 6.5

The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...

Published: Apr 21, 2026
Source: NVD
CVE-2026-40497 HIGH - 8.1

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<object>` but does NOT strip `<style>` tags. The mailbox signature field is saved via POST ...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-6058 MEDIUM - 4.5

** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authentica...

Published: Apr 21, 2026
Source: NVD
CVE-2026-40496 CRITICAL - 9.1

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthenti...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-40250 HIGH - 7.1

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_p...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 21, 2026
Source: NVD
CVE-2026-40244 HIGH - 7.1

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1722` performs `curc->width * curc->height`...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 21, 2026
Source: NVD
CVE-2026-39973 HIGH - 7.1

Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (`apktool d`). This is a se...

Vendor: iBotPeaches
Product: Apktool
Published: Apr 21, 2026
Source: NVD
CVE-2026-39886 MEDIUM - 5.3

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Versions 3.4.0 through 3.4.9 have a signed integer overflow vulnerability in OpenEXR's HTJ2K (High-Throughput JPEG 2000) decompression path. The `ht_u...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 21, 2026
Source: NVD
CVE-2026-39866 HIGH - 8.8

Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.

Vendor: LawnchairLauncher
Product: lawnchair
Published: Apr 21, 2026
Source: NVD

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5...

Vendor: openbao
Product: openbao
Published: Apr 21, 2026
Source: NVD