Total CVEs

126,094

Critical Severity

2,287

High Severity

7,907

Last 7 Days

1,157
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 261 - 280 of 897 CVEs

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the app...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was presented to the handler....

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-5420 LOW - 2.5

A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. Performing a manipulation of the argument AES_IV/AES_PASSWORD results in use of hard-coded cryptograp...

Published: Apr 02, 2026
Source: NVD

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2026-5413 LOW - 3.7

A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails leads to information disclosure. The attack is possible to be carried out remot...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5370 LOW - 3.5

A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the att...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5360 LOW - 3.7

A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The explo...

Published: Apr 02, 2026
Source: NVD

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

Vendor: OpenBSD
Product: OpenSSH
Published: Apr 02, 2026
Source: NVD

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

Vendor: OpenBSD
Product: OpenSSH
Published: Apr 02, 2026
Source: NVD

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

Vendor: OpenBSD
Product: OpenSSH
Published: Apr 02, 2026
Source: NVD

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal ...

Vendor: SignalK
Product: signalk-server
Published: Apr 02, 2026
Source: NVD

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content-Type header contains multiple boundary parameters, Rack selects the last one ra...

Vendor: rack
Product: rack
Published: Apr 02, 2026
Source: NVD
CVE-2026-5332 LOW - 3.5

A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available an...

Vendor: xiaopi
Product: panel
Published: Apr 02, 2026
Source: NVD
CVE-2026-5325 LOW - 3.5

A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create Ticket. This manipulation of the argument Description causes cross site scripting. Remote exploitatio...

Published: Apr 02, 2026
Source: NVD

Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the redirect URL as a query parameter. Refresh tokens in URLs are logged in browser history, server access logs, HTTP Referer header...

Vendor: go
Product: github.com/nhost/nhost
Published: Apr 01, 2026
Source: GitHub

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

Vendor: IBM
Product: Aspera Shares
Published: Apr 01, 2026
Source: NVD

Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an authenticated NetworkManager to modify any subscriber's p...

Vendor: go
Product: github.com/ellanetworks/core
Published: Apr 01, 2026
Source: GitHub

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD