Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 321 - 340 of 22,519 CVEs

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in the mix.lock file to ensure reproducible and integrity-checked builds. However, Hex.R...

Vendor: hexpm
Product: hex
Published: Apr 30, 2026
Source: NVD
CVE-2026-42191 MEDIUM - 6.5

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

Vendor: nuget
Product: OpenTelemetry.Exporter.OpenTelemetryProtocol
Published: Apr 30, 2026
Source: GitHub

Clerk has an authorization bypass when combining organization, billing, or reverification checks

Vendor: npm
Product: @clerk/shared
Published: Apr 30, 2026
Source: GitHub
CVE-2026-3833 MEDIUM - 6.5

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting ...

Published: Apr 30, 2026
Source: NVD
CVE-2026-3832 LOW - 3.7

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enable...

Published: Apr 30, 2026
Source: NVD
CVE-2026-36766 MEDIUM - 5.4

Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions.

Published: Apr 30, 2026
Source: NVD

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36763 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.

Published: Apr 30, 2026
Source: NVD

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36761 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the msgContent parameter.

Published: Apr 30, 2026
Source: NVD
CVE-2026-33845 HIGH - 7.5

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Apr 30, 2026
Source: NVD
CVE-2026-42449 HIGH - 8.5

n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders

Vendor: npm
Product: n8n-mcp
Published: Apr 30, 2026
Source: GitHub

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

Vendor: pip
Product: ckan
Published: Apr 30, 2026
Source: GitHub

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Vendor: pip
Product: weblate
Published: Apr 30, 2026
Source: GitHub
CVE-2026-41519 MEDIUM - 4.2

Weblate Doesn't Invalidate API Token on Password Change

Vendor: pip
Product: weblate
Published: Apr 30, 2026
Source: GitHub
CVE-2026-40281 CRITICAL - 10.0

Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: Apr 30, 2026
Source: GitHub

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

Vendor: npm
Product: @jupyter-notebook/help-extension
Published: Apr 30, 2026
Source: GitHub
CVE-2026-39383 HIGH - 8.6

Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: Apr 30, 2026
Source: GitHub
CVE-2026-40280 CRITICAL - 9.3

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: Apr 30, 2026
Source: GitHub
CVE-2026-36767 CRITICAL - 10.0

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

Published: Apr 30, 2026
Source: NVD