Total CVEs

149,276

Critical Severity

4,762

High Severity

17,010

Last 7 Days

3,286
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 24,581 - 24,600 of 45,681 CVEs
CVE-2026-1949 CRITICAL - 9.8

Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.

Published: Apr 24, 2026
Source: NVD
CVE-2026-6947 HIGH - 7.5

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device.

Published: Apr 24, 2026
Source: NVD
CVE-2026-6393 MEDIUM - 4.3

The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possib...

Published: Apr 24, 2026
Source: NVD
CVE-2026-5488 MEDIUM - 5.3

The ExactMetrics โ€“ Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is loca...

Published: Apr 24, 2026
Source: NVD
CVE-2026-41485 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller ...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41430 MEDIUM - 6.1

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS. The patch in commit 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 fixes the issue by restricting redirec...

Vendor: frappe
Product: press
Published: Apr 24, 2026
Source: NVD
CVE-2026-41324 HIGH - 7.5

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client....

Vendor: patrickjuchli
Product: basic-ftp
Published: Apr 24, 2026
Source: NVD
CVE-2026-41323 HIGH - 8.1

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service UR...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41319 MEDIUM - 6.5

MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechani...

Vendor: jstedfast
Product: MailKit
Published: Apr 24, 2026
Source: NVD
CVE-2026-41318 MEDIUM - 5.4

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's in-chat markdown renderer has an unsafe custom rule for images that interpolates the markdown image's `alt` text into an HTML `...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Apr 24, 2026
Source: NVD
CVE-2026-41068 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating the `URLPath` field. However, the ConfigMap context loader has the identical vulnerability โ€” the ...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-2028 MEDIUM - 5.3

The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in all versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with ...

Published: Apr 24, 2026
Source: NVD
CVE-2026-41317 HIGH - 7.5

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to database and it is also accessible via GET method. The patch in commit ...

Vendor: frappe
Product: press
Published: Apr 24, 2026
Source: NVD
CVE-2026-41316 HIGH - 8.1

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other publi...

Vendor: ruby
Product: erb
Published: Apr 24, 2026
Source: NVD
CVE-2026-41309 HIGH - 8.2

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file siz...

Vendor: opensource-socialnetwork
Product: opensource-socialnetwork
Published: Apr 24, 2026
Source: NVD
CVE-2026-41305 MEDIUM - 6.1

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTM...

Vendor: postcss
Product: postcss
Published: Apr 24, 2026
Source: NVD
CVE-2026-40254 MEDIUM - 4.2

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but misses `..` when it's the last component with ...

Vendor: FreeRDP
Product: FreeRDP
Published: Apr 24, 2026
Source: NVD
CVE-2026-33317 HIGH - 8.7

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()` in `ta/pkcs11/src/object.c` can lead to out-of-bounds ...

Vendor: OP-TEE
Product: optee_os
Published: Apr 24, 2026
Source: NVD
CVE-2026-33208 HIGH - 8.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into a shell command string that is subsequently...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-33078 CRITICAL - 9.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through m...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD