Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,958
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,741 - 4,760 of 12,538 CVEs
CVE-2026-32834 HIGH - 7.5

Easy PayPal Events & Tickets plugin for WordPress version 1.3 and earlier contain a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated remote attackers to bypass hash verification by supplying 'test' as the hash parameter. At...

Vendor: Scott Paterson
Product: easy-paypal-events-tickets
Published: May 04, 2026
Source: NVD
CVE-2026-29004 HIGH - 8.1

BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SE...

Vendor: vda-linux
Product: busybox_mirror
Published: May 04, 2026
Source: NVD
CVE-2026-0073 HIGH - 8.8

In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for ex...

Vendor: google
Product: android
Published: May 04, 2026
Source: NVD
CVE-2026-40076 HIGH - 8.7

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint at POST `/openmrs/ws/rest/v1/module` is vulnerable to a Zip Slip path traversal attack. During automatic extraction of uploaded .omod a...

Vendor: maven
Product: org.openmrs.web:openmrs-web
Published: May 04, 2026
Source: GitHub
CVE-2026-39852 HIGH - 8.2

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP pat...

Vendor: maven
Product: io.quarkus:quarkus-vertx-http
Published: May 04, 2026
Source: GitHub
CVE-2026-40075 HIGH - 7.5

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnerable to a path traversal attack. The ModuleResourcesServlet constructs a filesystem path from user-con...

Vendor: maven
Product: org.openmrs.web:openmrs-web
Published: May 04, 2026
Source: GitHub
CVE-2026-42440 HIGH - 7.5

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field from...

Vendor: Apache Software Foundation
Product: Apache OpenNLP
Published: May 04, 2026
Source: NVD
CVE-2026-42372 HIGH - 8.8

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The...

Vendor: D-Link
Product: DIR-605L Firmware
Published: May 04, 2026
Source: NVD
CVE-2026-42079 HIGH - 8.6

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.

Vendor: icip-cas
Product: PPTAgent
Published: May 04, 2026
Source: NVD
CVE-2026-42075 HIGH - 8.1

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enablin...

Vendor: EvoMap
Product: evolver
Published: May 04, 2026
Source: NVD
CVE-2026-37461 HIGH - 7.5

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Vendor: osrg
Product: gobgp
Published: May 04, 2026
Source: NVD
CVE-2026-29514 HIGH - 8.8

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the env...

Vendor: netbox-community
Product: netbox
Published: May 04, 2026
Source: NVD
CVE-2026-24082 HIGH - 7.8

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47408 HIGH - 7.8

Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47407 HIGH - 7.8

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47405 HIGH - 7.8

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2026-40563 HIGH - 7.1

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data ...

Vendor: Apache Software Foundation
Product: Apache Atlas
Published: May 04, 2026
Source: NVD
CVE-2026-36365 HIGH - 7.8

An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp

Published: May 04, 2026
Source: NVD
CVE-2026-29169 HIGH - 7.5

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlie...

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-23918 HIGH - 8.8

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD