Total CVEs

126,186

Critical Severity

2,292

High Severity

7,951

Last 7 Days

1,204
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,481 - 2,500 of 22,591 CVEs
CVE-2026-39112 MEDIUM - 5.4

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisitor...

Published: Apr 20, 2026
Source: NVD
CVE-2026-39111 HIGH - 7.5

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve sensitive user data.

Published: Apr 20, 2026
Source: NVD
CVE-2026-39110 HIGH - 8.2

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sen...

Published: Apr 20, 2026
Source: NVD
CVE-2026-39109 CRITICAL - 9.4

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database c...

Published: Apr 20, 2026
Source: NVD
CVE-2026-26399 MEDIUM - 5.3

A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it is stored in a global timer handle registry. After the functio...

Published: Apr 20, 2026
Source: NVD
CVE-2026-23758 MEDIUM - 5.4

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Cont...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23757 MEDIUM - 5.4

GFI HelpDesk before 4.99.10Ā contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaScript into the report title field when creating or editing a re...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23756 MEDIUM - 5.4

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can in...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23753 MEDIUM - 4.8

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An a...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23752 MEDIUM - 4.8

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can inj...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-6662 HIGH - 7.3

A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remote...

Published: Apr 20, 2026
Source: NVD
CVE-2026-41445 HIGH - 8.8

KissFFT before commitĀ 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther*(dimReal+2)*sizeof(kiss_fft_scalar) overflows signed 32-bit integer arithmetic before being widened to size_t, causing malloc()...

Vendor: mborgerding
Product: kissfft
Published: Apr 20, 2026
Source: NVD
CVE-2026-40488 HIGH - 8.8

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option file upload in OpenMage LTS uses an incomplete bloc...

Vendor: OpenMage
Product: magento-lts
Published: Apr 20, 2026
Source: NVD
CVE-2026-40098 MEDIUM - 5.4

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the shared wishlist add-to-cart endpoint authorizes access with a public `sha...

Vendor: OpenMage
Product: magento-lts
Published: Apr 20, 2026
Source: NVD
CVE-2026-35154 MEDIUM - 6.3

Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could poten...

Vendor: Dell
Product: PowerProtect Data Domain appliances
Published: Apr 20, 2026
Source: NVD
CVE-2026-30269 CRITICAL - 9.9

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privil...

Vendor: doorman
Product: doorman
Published: Apr 20, 2026
Source: NVD
CVE-2026-30266 HIGH - 7.8

Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file

Vendor: deepcool
Product: deepcreative
Published: Apr 20, 2026
Source: NVD
CVE-2026-28684 MEDIUM - 6.6

python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when ...

Vendor: theskumar
Product: python-dotenv
Published: Apr 20, 2026
Source: NVD
CVE-2026-26951 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerab...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 20, 2026
Source: NVD
CVE-2026-26943 HIGH - 7.2

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 20, 2026
Source: NVD