Total CVEs

150,604

Critical Severity

4,940

High Severity

17,474

Last 7 Days

2,190
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 27,581 - 27,600 of 47,009 CVEs

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowerca...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP U...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD
CVE-2026-35031 CRITICAL - 9.9

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. T...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD
CVE-2026-33023 HIGH - 7.8

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path manually frees the sixel_frame_t object and its...

Vendor: saitoha
Product: libsixel
Published: Apr 14, 2026
Source: NVD
CVE-2026-33021 HIGH - 7.3

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer directly in frame->pixels without making a de...

Vendor: saitoha
Product: libsixel
Published: Apr 14, 2026
Source: NVD
CVE-2026-27301 MEDIUM - 5.5

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a...

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27300 MEDIUM - 5.5

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim mus...

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27299 MEDIUM - 6.3

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation of this issue requires user interaction i...

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27298 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi...

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27297 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27296 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27295 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27294 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. ...

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27293 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27292 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-27290 HIGH - 8.6

Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an attacker could mod...

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD
CVE-2026-40320 MEDIUM - 7.8

Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rendered the rule parameter through Jinja2's default Template() constructor, silently interpreting template expressions at runtime. If check definitions are loaded from an untruste...

Vendor: pip
Product: giskard-checks
Published: Apr 14, 2026
Source: GitHub

Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern directly to Python's re.search() without any timeout or complexity guard. A crafted regex pattern can trigger catastrophic backtrack...

Vendor: pip
Product: giskard-checks
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40890 HIGH - 7.5

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or...

Vendor: go
Product: github.com/gomarkdown/markdown
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40887 CRITICAL - 9.1

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression wi...

Vendor: npm
Product: @vendure/core
Published: Apr 14, 2026
Source: GitHub