Total CVEs

119,913

Critical Severity

1,691

High Severity

5,751

Last 7 Days

1,586
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 16,318 CVEs
CVE-2025-71279 CRITICAL - 9.8

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2025-71278 HIGH - 8.8

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowing client applications to gain access beyond their intended authorization level.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2025-13855 HIGH - 7.6

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Vendor: IBM
Product: Storage Protect Server
Published: Apr 01, 2026
Source: NVD
CVE-2024-58342 MEDIUM - 6.3

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user credentials, or host mis...

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD
CVE-2026-34604 HIGH - 7.1

@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions

Vendor: npm
Product: @tinacms/graphql
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34603 HIGH - 7.1

@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions

Vendor: npm
Product: @tinacms/graphql
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34601 HIGH - 7.5

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

Vendor: npm
Product: xmldom
Published: Apr 01, 2026
Source: GitHub
CVE-2026-5240 MEDIUM - 4.3

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclos...

Published: Apr 01, 2026
Source: NVD
CVE-2026-5238 HIGH - 7.3

A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed fro...

Published: Apr 01, 2026
Source: NVD
CVE-2026-4668 MEDIUM - 6.5

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of ...

Published: Apr 01, 2026
Source: NVD

Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash

Vendor: erlang
Product: ash
Published: Apr 01, 2026
Source: GitHub

YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"

Vendor: composer
Product: yeswiki/yeswiki
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34531 MEDIUM - 6.5

Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client

Vendor: pip
Product: Flask-HTTPAuth
Published: Mar 31, 2026
Source: GitHub
CVE-2026-34530 MEDIUM - 6.9

File Browser vulnerable to Stored Cross-site Scripting via text/template branding injection

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Mar 31, 2026
Source: GitHub
CVE-2026-34528 HIGH - 8.1

File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Mar 31, 2026
Source: GitHub
CVE-2026-34529 HIGH - 7.6

File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Mar 31, 2026
Source: GitHub
CVE-2026-5237 HIGH - 7.3

A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_user.php of the component Parameter Handler. Performing a manipulation of the argument ID results in sql injection. The attack is possible...

Published: Mar 31, 2026
Source: NVD
CVE-2026-5236 MEDIUM - 5.3

A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of the component DSI v1 Parser. Such manipulation of the argument n_presentations leads to heap-based buffer overflow. The attack needs to be performed loc...

Published: Mar 31, 2026
Source: NVD
CVE-2026-5235 MEDIUM - 5.3

A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation causes heap-based buffer overflow. The attack needs to be launched locally. The exploit has been publ...

Published: Mar 31, 2026
Source: NVD
CVE-2026-34556 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a heap-buffer-overflow (HBO) in icAnsiToUtf8() in the XML conversion path. The issue is triggered by a crafted ICC profile which causes icAnsiToUtf8(std::string&, char ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD