Total CVEs

149,881

Critical Severity

4,890

High Severity

17,337

Last 7 Days

1,700
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 26,841 - 26,860 of 46,286 CVEs
CVE-2026-4812 MEDIUM - 5.3

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions withou...

Published: Apr 15, 2026
Source: NVD

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially craft...

Vendor: radareorg
Product: radare2
Published: Apr 15, 2026
Source: NVD

immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the shared album functionality, where the album name is inserted unsanitized into a <meta> tag in api.service.ts. A registered attacker can create a s...

Vendor: immich-app
Product: immich
Published: Apr 15, 2026
Source: NVD
CVE-2026-33806 HIGH - 7.5

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= ...

Vendor: fastify
Product: fastify
Published: Apr 15, 2026
Source: NVD
CVE-2026-2834 HIGH - 7.2

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ parameter in all versions up to, and including, 3.32.3 due to insufficient input sanitization and output escaping. This makes it possible for una...

Published: Apr 15, 2026
Source: NVD
CVE-2026-2396 MEDIUM - 4.4

The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event description in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1555 CRITICAL - 9.8

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1541 MEDIUM - 4.3

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.15.1. This is due to the plugin's `fusion_get_post_custom_field()` function failing to validate whether metadata keys are protected (underscore-prefixed). This...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1509 MEDIUM - 5.4

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up to, and including, 3.15.1. This is due to the plugin's `output_action_hook()` function accepting user-controlled input to trigger any registered WordPress action hook without...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1314 MEDIUM - 5.3

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthentic...

Published: Apr 15, 2026
Source: NVD
CVE-2025-54550 HIGH - 8.1

The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. Since the UI users are already highly tru...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 15, 2026
Source: NVD
CVE-2025-15470 MEDIUM - 6.5

The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in the akd_required_plugin_callback function in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to de...

Vendor: DesigningMedia
Product: Eleganzo
Published: Apr 15, 2026
Source: NVD
CVE-2026-40688 HIGH - 7.2

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

Vendor: Fortinet
Product: FortiWeb
Published: Apr 14, 2026
Source: NVD
CVE-2026-39399 CRITICAL - 9.6

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a crafted nuspec file with malicious metadata, leading to cross package metadata injection that may r...

Vendor: NuGet
Product: NuGetGallery
Published: Apr 14, 2026
Source: NVD
CVE-2026-39387 HIGH - 7.2

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to ...

Vendor: BoidCMS
Product: BoidCMS
Published: Apr 14, 2026
Source: NVD
CVE-2026-35589 HIGH - 8.0

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The original fix changed the binding from 0.0.0....

Vendor: HKUDS
Product: nanobot
Published: Apr 14, 2026
Source: NVD
CVE-2026-35034 MEDIUM - 6.5

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authenticated user can create groups with names of unlimited size due to insufficient input validation. By s...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowerca...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP U...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD
CVE-2026-35031 CRITICAL - 9.9

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. T...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD