Total CVEs

126,116

Critical Severity

2,290

High Severity

7,924

Last 7 Days

1,178
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 281 - 300 of 22,521 CVEs

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.

Vendor: Exim
Product: Exim
Published: Apr 30, 2026
Source: NVD
CVE-2026-40685 MEDIUM - 6.5

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

Vendor: Exim
Product: Exim
Published: Apr 30, 2026
Source: NVD
CVE-2026-40684 MEDIUM - 5.9

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Vendor: Exim
Product: Exim
Published: Apr 30, 2026
Source: NVD
CVE-2026-3345 MEDIUM - 6.5

IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

Published: Apr 30, 2026
Source: NVD
CVE-2026-2311 MEDIUM - 6.4

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

Vendor: ibm
Product: i
Published: Apr 30, 2026
Source: NVD
CVE-2026-1577 MEDIUM - 6.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.

Vendor: ibm
Product: db2
Published: Apr 30, 2026
Source: NVD
CVE-2025-36335 MEDIUM - 6.2

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.

Vendor: IBM
Product: watsonx.data intelligence
Published: Apr 30, 2026
Source: NVD
CVE-2025-36180 MEDIUM - 5.3

IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restrictions.

Vendor: IBM
Product: watsonx.data
Published: Apr 30, 2026
Source: NVD
CVE-2025-36122 MEDIUM - 6.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.

Vendor: IBM
Product: Db2
Published: Apr 30, 2026
Source: NVD
CVE-2025-14688 MEDIUM - 5.3

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.

Vendor: IBM
Product: Db2
Published: Apr 30, 2026
Source: NVD
CVE-2026-7501 LOW - 3.5

A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The ex...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7435 HIGH - 7.2

SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic endpoint to execute arbitr...

Published: Apr 30, 2026
Source: NVD
CVE-2026-6539 MEDIUM - 4.4

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through communit...

Vendor: notepad-plus-plus
Product: notepad\+\+
Published: Apr 30, 2026
Source: NVD
CVE-2026-4503 HIGH - 7.5

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.

Published: Apr 30, 2026
Source: NVD
CVE-2026-4502 MEDIUM - 6.5

IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

Published: Apr 30, 2026
Source: NVD

CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service.

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD

CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD

CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD
CVE-2026-3346 MEDIUM - 6.4

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess...

Published: Apr 30, 2026
Source: NVD
CVE-2026-3340 MEDIUM - 6.5

IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Published: Apr 30, 2026
Source: NVD