Total CVEs

125,862

Critical Severity

2,275

High Severity

7,879

Last 7 Days

1,162
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 421 - 440 of 7,579 CVEs
CVE-2026-5367 HIGH - 8.6

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the...

Published: Apr 24, 2026
Source: NVD
CVE-2026-23902 HIGH - 8.1

Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1.  Users are recommended to upg...

Vendor: Apache Software Foundation
Product: Apache DolphinScheduler
Published: Apr 24, 2026
Source: NVD
CVE-2026-41044 HIGH - 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validati...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All
Published: Apr 24, 2026
Source: NVD
CVE-2026-40466 HIGH - 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via ...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
Published: Apr 24, 2026
Source: NVD
CVE-2026-21728 HIGH - 7.5

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).

Vendor: Grafana
Product: Tempo
Published: Apr 24, 2026
Source: NVD
CVE-2026-5364 HIGH - 8.1

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attack...

Published: Apr 24, 2026
Source: NVD
CVE-2026-6947 HIGH - 7.5

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device.

Published: Apr 24, 2026
Source: NVD
CVE-2026-41485 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller ...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41324 HIGH - 7.5

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client....

Vendor: patrickjuchli
Product: basic-ftp
Published: Apr 24, 2026
Source: NVD
CVE-2026-41323 HIGH - 8.1

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service UR...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41068 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating the `URLPath` field. However, the ConfigMap context loader has the identical vulnerability — the ...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41317 HIGH - 7.5

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to database and it is also accessible via GET method. The patch in commit ...

Vendor: frappe
Product: press
Published: Apr 24, 2026
Source: NVD
CVE-2026-41316 HIGH - 8.1

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other publi...

Vendor: ruby
Product: erb
Published: Apr 24, 2026
Source: NVD
CVE-2026-41309 HIGH - 8.2

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file siz...

Vendor: opensource-socialnetwork
Product: opensource-socialnetwork
Published: Apr 24, 2026
Source: NVD
CVE-2026-33317 HIGH - 8.7

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()` in `ta/pkcs11/src/object.c` can lead to out-of-bounds ...

Vendor: OP-TEE
Product: optee_os
Published: Apr 24, 2026
Source: NVD
CVE-2026-33208 HIGH - 8.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into a shell command string that is subsequently...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-33077 HIGH - 7.5

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-41325 HIGH - 8.8

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also possible to custom...

Vendor: getkirby
Product: kirby
Published: Apr 24, 2026
Source: NVD
CVE-2026-40623 HIGH - 8.1

A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watc...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-39462 HIGH - 8.1

A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD