Total CVEs

150,903

Critical Severity

5,032

High Severity

17,664

Last 7 Days

2,103
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 28,301 - 28,320 of 47,308 CVEs

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL ter...

Vendor: jqlang
Product: jq
Published: Apr 13, 2026
Source: NVD
CVE-2026-39956 MEDIUM - 6.1

jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() ch...

Vendor: jqlang
Product: jq
Published: Apr 13, 2026
Source: NVD
CVE-2026-6224 HIGH - 7.3

A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiat...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6220 MEDIUM - 4.7

A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServer of the file ServerService.java of the component Video File Download URL Handler. Such manipulation of the argument streamIp leads to server-side request forgery. It is possible t...

Published: Apr 13, 2026
Source: NVD

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Published: Apr 13, 2026
Source: NVD
CVE-2026-40312 MEDIUM - 6.2

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19.

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-40311 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions ...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-40310 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and 7...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-40183 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-40169 MEDIUM - 6.2

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-34238 MEDIUM - 5.1

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, an integer overflow in the despeckle operation causes a heap buffer overflow on 32-bit builds that will result in an out of bounds write. This issue has been ...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-33947 MEDIUM - 6.2

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can suppl...

Vendor: jqlang
Product: jq
Published: Apr 13, 2026
Source: NVD
CVE-2026-33908 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When M...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-33905 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. Th...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-33902 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression. Thi...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-22566 HIGH - 7.5

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi ...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD
CVE-2026-22565 HIGH - 7.5

An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update Uni...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD
CVE-2026-22564 CRITICAL - 9.8

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitiga...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD
CVE-2026-22563 CRITICAL - 9.8

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi Pla...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD
CVE-2026-22562 CRITICAL - 9.8

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio ...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD