Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,704
Quick preset (or use dates below)
Clear Filters
Showing 4,881 - 4,900 of 13,837 CVEs
CVE-2026-42080 MEDIUM - 4.6

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary file write vulnerability via `save_generated_slides`. This issue has been patched via commit 418491a.

Vendor: icip-cas
Product: PPTAgent
Published: May 04, 2026
Source: NVD
CVE-2026-42078 MEDIUM - 4.6

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This issue has been patched via commit 418491a.

Vendor: icip-cas
Product: PPTAgent
Published: May 04, 2026
Source: NVD
CVE-2026-42077 MEDIUM - 5.2

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The vulnerability exists in...

Vendor: EvoMap
Product: evolver
Published: May 04, 2026
Source: NVD
CVE-2026-38669 MEDIUM - 6.1

wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.

Published: May 04, 2026
Source: NVD
CVE-2026-25266 MEDIUM - 5.5

Memory corruption while processing IOCTL command when device is in power-save state.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47406 MEDIUM - 6.1

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47404 MEDIUM - 6.5

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47403 MEDIUM - 6.5

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47401 MEDIUM - 6.5

Transient DOS when processing target power rate tables during channel configuration.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2026-35527 MEDIUM - 4.3

Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs...

Vendor: go
Product: github.com/lxc/incus/v6/cmd/incusd
Published: May 04, 2026
Source: GitHub
CVE-2026-37458 MEDIUM - 6.5

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

Vendor: frrouting
Product: frrouting
Published: May 04, 2026
Source: NVD
CVE-2025-70071 MEDIUM - 5.9

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()

Published: May 04, 2026
Source: NVD
CVE-2026-33523 MEDIUM - 6.5

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-33007 MEDIUM - 5.3

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-33006 MEDIUM - 4.8

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2025-70072 MEDIUM - 6.5

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components

Published: May 04, 2026
Source: NVD
CVE-2025-70070 MEDIUM - 6.5

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()

Published: May 04, 2026
Source: NVD
CVE-2026-34032 MEDIUM - 5.3

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-33857 MEDIUM - 5.3

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-31205 MEDIUM - 5.7

Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function

Published: May 04, 2026
Source: NVD