Total CVEs

125,862

Critical Severity

2,275

High Severity

7,879

Last 7 Days

1,162
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 21 - 40 of 8,347 CVEs
CVE-2026-4502 MEDIUM - 6.5

IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could sendΒ a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

Published: Apr 30, 2026
Source: NVD
CVE-2026-3346 MEDIUM - 6.4

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess...

Published: Apr 30, 2026
Source: NVD
CVE-2026-3340 MEDIUM - 6.5

IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Published: Apr 30, 2026
Source: NVD
CVE-2026-28532 MEDIUM - 6.5

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer...

Vendor: FRRouting
Product: frr
Published: Apr 30, 2026
Source: NVD
CVE-2026-7429 MEDIUM - 4.6

SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can exploit improper output enc...

Published: Apr 30, 2026
Source: NVD
CVE-2026-40603 MEDIUM - 6.5

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that returns a project's report data to any authenticated member of the same team, even when that user does...

Vendor: chartbrew
Product: chartbrew
Published: Apr 30, 2026
Source: NVD
CVE-2026-35514 MEDIUM - 6.5

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token, authentication header, or session. Any unauthenticated attacker can call this endpoint ...

Vendor: chartbrew
Product: chartbrew
Published: Apr 30, 2026
Source: NVD
CVE-2026-42191 MEDIUM - 6.5

OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter

Vendor: nuget
Product: OpenTelemetry.Exporter.OpenTelemetryProtocol
Published: Apr 30, 2026
Source: GitHub
CVE-2026-3833 MEDIUM - 6.5

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting ...

Published: Apr 30, 2026
Source: NVD
CVE-2026-36766 MEDIUM - 5.4

Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36763 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36761 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the msgContent parameter.

Published: Apr 30, 2026
Source: NVD

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

Vendor: pip
Product: ckan
Published: Apr 30, 2026
Source: GitHub

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Vendor: pip
Product: weblate
Published: Apr 30, 2026
Source: GitHub
CVE-2026-41519 MEDIUM - 4.2

Weblate Doesn't Invalidate API Token on Password Change

Vendor: pip
Product: weblate
Published: Apr 30, 2026
Source: GitHub
CVE-2026-36764 MEDIUM - 5.0

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36757 MEDIUM - 4.3

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-38940 MEDIUM - 6.1

Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component

Published: Apr 30, 2026
Source: NVD
CVE-2026-38939 MEDIUM - 6.1

Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component

Published: Apr 30, 2026
Source: NVD
CVE-2026-36759 MEDIUM - 6.5

A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD