Total CVEs

149,960

Critical Severity

4,910

High Severity

17,395

Last 7 Days

1,772
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 26,961 - 26,980 of 46,365 CVEs
CVE-2026-39971 HIGH - 7.2

Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_SERVER['HTTP_HOST'] directly into the Message-ID SMTP header without validation, and the existing sanitization function serendipity_isResponse...

Vendor: composer
Product: s9y/serendipity
Published: Apr 14, 2026
Source: GitHub
CVE-2026-39963 MEDIUM - 6.9

Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] without validation as the domain parameter of setcookie(). An attacker who can influence the Host header at logi...

Vendor: composer
Product: s9y/serendipity
Published: Apr 14, 2026
Source: GitHub
CVE-2026-39884 HIGH - 8.3

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/port_forward.ts, where a kubectl command is constructed via string concatenation with user-controlled...

Vendor: npm
Product: mcp-server-kubernetes
Published: Apr 14, 2026
Source: GitHub
CVE-2026-39842 CRITICAL - 10.0

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's ScriptEngine.eval() ...

Vendor: maven
Product: io.openremote:openremote-manager
Published: Apr 14, 2026
Source: GitHub
CVE-2026-34457 CRITICAL - 9.1

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-a...

Vendor: go
Product: github.com/oauth2-proxy/oauth2-proxy/v7
Published: Apr 14, 2026
Source: GitHub

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout flow, a user may be show...

Vendor: go
Product: github.com/oauth2-proxy/oauth2-proxy/v7
Published: Apr 14, 2026
Source: GitHub

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() ...

Vendor: go
Product: github.com/containers/podman/v4
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40885 HIGH - 8.8

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected folders are logged before authorization is enforced, and the c...

Vendor: go
Product: github.com/patrickhener/goshs/v2
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40883 MEDIUM - 8.1

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because gos...

Vendor: go
Product: github.com/patrickhener/goshs/v2
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40884 CRITICAL - 9.8

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accepts that configuration but does not install a...

Vendor: go
Product: github.com/patrickhener/goshs
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40876 HIGH - 8.8

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expose...

Vendor: go
Product: github.com/patrickhener/goshs
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40870 HIGH - 7.5

Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field in the API allows access to all commentable resources within the platform, without any permission checks. All Decidim instances are impacted that have...

Vendor: rubygems
Product: decidim-comments
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40869 HIGH - 7.5

Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is e...

Vendor: rubygems
Product: decidim-core
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40291 HIGH - 8.8

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenticated user with ROLE_STUDENT to escalate their privileges to ROLE_ADMIN by modifying the roles field ...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 14, 2026
Source: NVD

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-ac...

Vendor: Unisys
Product: WebPerfect Image Suite
Published: Apr 14, 2026
Source: NVD

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques....

Vendor: Unisys
Product: WebPerfect Image Suite
Published: Apr 14, 2026
Source: NVD
CVE-2026-35196 HIGH - 8.8

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code retrieved from the session variable $_SESSION[...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 14, 2026
Source: NVD
CVE-2026-34631 HIGH - 7.8

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: InCopy
Published: Apr 14, 2026
Source: NVD
CVE-2026-34619 HIGH - 7.7

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or dire...

Vendor: Adobe
Product: ColdFusion
Published: Apr 14, 2026
Source: NVD
CVE-2026-34602 HIGH - 7.1

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object Reference (IDOR), allowing an authenticated attacker to modify the user parameter in the request body to enroll any arbitrary user int...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 14, 2026
Source: NVD