Total CVEs

150,604

Critical Severity

4,940

High Severity

17,474

Last 7 Days

2,190
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 27,561 - 27,580 of 47,009 CVEs
CVE-2026-5397 HIGH - 7.8

It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL is...

Published: Apr 15, 2026
Source: NVD
CVE-2026-26291 MEDIUM - 5.4

Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed in a user's web browser.

Vendor: GROWI, Inc.
Product: GROWI
Published: Apr 15, 2026
Source: NVD

Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.

Published: Apr 15, 2026
Source: NVD
CVE-2026-4812 MEDIUM - 5.3

The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions withou...

Published: Apr 15, 2026
Source: NVD

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially craft...

Vendor: radareorg
Product: radare2
Published: Apr 15, 2026
Source: NVD

immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the shared album functionality, where the album name is inserted unsanitized into a <meta> tag in api.service.ts. A registered attacker can create a s...

Vendor: immich-app
Product: immich
Published: Apr 15, 2026
Source: NVD
CVE-2026-33806 HIGH - 7.5

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= ...

Vendor: fastify
Product: fastify
Published: Apr 15, 2026
Source: NVD
CVE-2026-2834 HIGH - 7.2

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ parameter in all versions up to, and including, 3.32.3 due to insufficient input sanitization and output escaping. This makes it possible for una...

Published: Apr 15, 2026
Source: NVD
CVE-2026-2396 MEDIUM - 4.4

The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event description in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1555 CRITICAL - 9.8

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1541 MEDIUM - 4.3

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.15.1. This is due to the plugin's `fusion_get_post_custom_field()` function failing to validate whether metadata keys are protected (underscore-prefixed). This...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1509 MEDIUM - 5.4

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up to, and including, 3.15.1. This is due to the plugin's `output_action_hook()` function accepting user-controlled input to trigger any registered WordPress action hook without...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1314 MEDIUM - 5.3

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthentic...

Published: Apr 15, 2026
Source: NVD
CVE-2025-54550 HIGH - 8.1

The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. Since the UI users are already highly tru...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 15, 2026
Source: NVD
CVE-2025-15470 MEDIUM - 6.5

The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in the akd_required_plugin_callback function in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to de...

Vendor: DesigningMedia
Product: Eleganzo
Published: Apr 15, 2026
Source: NVD
CVE-2026-40688 HIGH - 7.2

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

Vendor: Fortinet
Product: FortiWeb
Published: Apr 14, 2026
Source: NVD
CVE-2026-39399 CRITICAL - 9.6

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a crafted nuspec file with malicious metadata, leading to cross package metadata injection that may r...

Vendor: NuGet
Product: NuGetGallery
Published: Apr 14, 2026
Source: NVD
CVE-2026-39387 HIGH - 7.2

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to ...

Vendor: BoidCMS
Product: BoidCMS
Published: Apr 14, 2026
Source: NVD
CVE-2026-35589 HIGH - 8.0

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The original fix changed the binding from 0.0.0....

Vendor: HKUDS
Product: nanobot
Published: Apr 14, 2026
Source: NVD
CVE-2026-35034 MEDIUM - 6.5

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authenticated user can create groups with names of unlimited size due to insufficient input validation. By s...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD