Total CVEs

149,482

Critical Severity

4,817

High Severity

17,191

Last 7 Days

2,792
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 26,181 - 26,200 of 45,887 CVEs
CVE-2026-2840 MEDIUM - 6.4

The Email Encoder โ€“ Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for ...

Published: Apr 16, 2026
Source: NVD
CVE-2026-6410 MEDIUM - 5.3

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured static root using path.join() without a containment check. A remote unauthenticated attacker can obtain dir...

Vendor: npm
Product: @fastify/static
Published: Apr 16, 2026
Source: NVD
CVE-2026-6270 CRITICAL - 9.1

@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application registers authentication middleware in a parent scope and then registers child plugins with @fastify/middie, the child scope does not inherit the pare...

Vendor: npm
Product: @fastify/middie
Published: Apr 16, 2026
Source: NVD
CVE-2026-5785 HIGH - 8.1

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.

Published: Apr 16, 2026
Source: NVD
CVE-2026-4160 MEDIUM - 5.3

The Fluent Forms โ€“ Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownersh...

Published: Apr 16, 2026
Source: NVD
CVE-2026-31987 MEDIUM - 7.5

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 16, 2026
Source: NVD
CVE-2026-6414 MEDIUM - 5.9

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. This mismatch allows attackers to bypass route-based middleware or guards that protect files served by @fastify/stati...

Vendor: npm
Product: @fastify/static
Published: Apr 16, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Apr 16, 2026
Source: NVD
CVE-2026-31843 CRITICAL - 9.8

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any() without authentication middleware, enabling ...

Vendor: goodoneuz
Product: pay-uz
Published: Apr 16, 2026
Source: NVD

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Vendor: Sparx Systems Pty Ltd.
Product: Sparx Enterprise Architect
Published: Apr 16, 2026
Source: NVD
CVE-2026-3489 HIGH - 7.5

The DirectoryPress โ€“ Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3369 MEDIUM - 5.4

The Better Find and Replace โ€“ AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3155 LOW - 3.1

The OneSignal โ€“ Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscri...

Published: Apr 16, 2026
Source: NVD
CVE-2025-12624 MEDIUM - 6.0

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequen...

Vendor: WSO2
Product: WSO2 Identity Server
Published: Apr 16, 2026
Source: NVD
CVE-2025-6024 MEDIUM - 6.1

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user's browser being redirected to a maliciou...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-8010 LOW - 3.5

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability, a malicious actor can read confidential files fr...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-4867 MEDIUM - 5.4

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-sit...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-10242 MEDIUM - 6.1

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim's browser. Successful exploitation can enable an ...

Vendor: WSO2
Product: WSO2 API Manager
Published: Apr 16, 2026
Source: NVD
CVE-2026-23772 HIGH - 7.3

Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: Storage Manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-2374 HIGH - 7.5

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD