Total CVEs

125,743

Critical Severity

2,263

High Severity

7,843

Last 7 Days

1,200
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 381 - 400 of 22,148 CVEs

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

Published: Apr 28, 2026
Source: NVD
CVE-2025-60887 MEDIUM - 5.3

An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under the cista::raw namespace are prone to reference tampering, wh...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7324 HIGH - 7.3

Memory safety bugs present in Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7323 HIGH - 7.3

Memory safety bugs present in Firefox ESR 140.10.0, Thunderbird ESR 140.10.0, Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7322 HIGH - 7.3

Memory safety bugs present in Firefox ESR 115.35.0, Firefox ESR 140.10.0, Thunderbird ESR 140.10.0, Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7321 CRITICAL - 9.6

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, and Firefox ESR 140.10.1.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7320 HIGH - 7.5

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, and Firefox ESR 115.35.1.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7289 HIGH - 8.8

A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: dlink
Product: dir-825m_firmware
Published: Apr 28, 2026
Source: NVD
CVE-2026-7288 HIGH - 8.8

A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to ...

Vendor: dlink
Product: dir-825m_firmware
Published: Apr 28, 2026
Source: NVD
CVE-2026-7283 MEDIUM - 4.7

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expired. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7282 MEDIUM - 4.7

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is p...

Published: Apr 28, 2026
Source: NVD

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0....

Vendor: Spring
Product: Spring gRPC
Published: Apr 28, 2026
Source: NVD
CVE-2026-40968 MEDIUM - 4.2

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Sp...

Vendor: Spring
Product: Spring gRPC
Published: Apr 28, 2026
Source: NVD

GNU nano creates the user’s ~/.local directory with overly permissive permissions when the directory does not exist yet. On first use of features requiring Cross-Desktop Group (XDG) data storage, nano explicitly requests directory mode 0777, making the directory world‑writable in environments where ...

Vendor: GNU
Product: nano
Published: Apr 28, 2026
Source: NVD
CVE-2026-27760 HIGH - 8.1

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string conte...

Vendor: opencats
Product: OpenCATS
Published: Apr 28, 2026
Source: NVD
CVE-2025-67223 HIGH - 7.5

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7281 LOW - 2.4

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be performed from remote. The e...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7272 HIGH - 7.3

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_matlab_code of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument scriptPath can lea...

Published: Apr 28, 2026
Source: NVD
CVE-2026-6706 MEDIUM - 6.5

Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.

Published: Apr 28, 2026
Source: NVD
CVE-2026-5944 HIGH - 8.2

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated...

Published: Apr 28, 2026
Source: NVD