Total CVEs

125,862

Critical Severity

2,275

High Severity

7,879

Last 7 Days

1,162
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 241 - 260 of 22,267 CVEs
CVE-2026-41643 HIGH - 7.5

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41642 HIGH - 7.5

GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub

CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 29, 2026
Source: GitHub

fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE

Vendor: maven
Product: org.hyperledger.fabric-sdk-java:fabric-sdk-java
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41255 MEDIUM - 6.1

CKAN has CSRF exemption primed by anonymous requests

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub

CKAN has no certificate validation on STMP connection

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40902 HIGH - 7.5

PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40863 HIGH - 7.5

PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub

PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41484 MEDIUM - 5.3

OneCollector exporter reads unbounded HTTP response bodies

Vendor: nuget
Product: OpenTelemetry.Exporter.OneCollector
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7426 HIGH - 8.1

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7425 MEDIUM - 6.5

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smalle...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7401 MEDIUM - 4.3

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results i...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7400 HIGH - 7.3

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit has...

Published: Apr 29, 2026
Source: NVD
CVE-2026-34965 HIGH - 8.8

Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP c...

Vendor: Cockpit
Product: Cockpit CMS
Published: Apr 29, 2026
Source: NVD
CVE-2018-25318 CRITICAL - 9.8

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS serve...

Vendor: Tenda
Product: FH303/A300
Published: Apr 29, 2026
Source: NVD
CVE-2018-25317 CRITICAL - 9.8

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted ad...

Vendor: Tenda
Product: W3002R
Published: Apr 29, 2026
Source: NVD
CVE-2018-25316 CRITICAL - 9.8

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS ser...

Vendor: Tenda
Product: W, R v
Published: Apr 29, 2026
Source: NVD
CVE-2018-25315 HIGH - 8.4

Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with structured exception handler (SEH) overwrite and shellcode to achieve code exec...

Vendor: Alloksoft
Product: Video Joiner
Published: Apr 29, 2026
Source: NVD
CVE-2018-25314 HIGH - 8.4

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handle...

Vendor: Alloksoft
Product: WMV to AVI MPEG DVD WMV Converter
Published: Apr 29, 2026
Source: NVD