Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,758
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,021 - 5,040 of 12,590 CVEs
CVE-2026-36762 HIGH - 8.8

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations.

Published: Apr 30, 2026
Source: NVD
CVE-2026-33845 HIGH - 7.5

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Apr 30, 2026
Source: NVD
CVE-2026-42449 HIGH - 8.5

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer constructor, getN8nApiClient(), and validateInstanceContext()), the synchronous URL validator in SSR...

Vendor: npm
Product: n8n-mcp
Published: Apr 30, 2026
Source: GitHub

In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-...

Vendor: npm
Product: @jupyter-notebook/help-extension
Published: Apr 30, 2026
Source: GitHub
CVE-2026-39383 HIGH - 8.6

Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The F...

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: Apr 30, 2026
Source: GitHub
CVE-2025-51846 HIGH - 7.5

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.

Vendor: CryptPad
Product: CryptPad
Published: Apr 30, 2026
Source: NVD
CVE-2022-50992 HIGH - 7.5

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowServi...

Vendor: Weaver Network Co., Ltd.
Product: E-cology
Published: Apr 30, 2026
Source: NVD
CVE-2026-5174 HIGH - 7.7

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Vendor: progress
Product: moveit_automation
Published: Apr 30, 2026
Source: NVD
CVE-2026-36960 HIGH - 8.8

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a...

Published: Apr 30, 2026
Source: NVD
CVE-2026-36340 HIGH - 8.1

An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

Published: Apr 30, 2026
Source: NVD
CVE-2026-36959 HIGH - 7.5

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized ...

Vendor: u-speed
Product: n300_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-36958 HIGH - 7.5

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the ro...

Vendor: u-speed
Product: n300_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-36957 HIGH - 7.5

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffer...

Vendor: dbitnet
Product: dbit_n300_t1_pro_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-36956 HIGH - 8.8

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An a...

Vendor: dbitnet
Product: dbit_n300_t1_pro_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-7246 HIGH - 7.2

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

Vendor: palletsprojects
Product: click
Published: Apr 30, 2026
Source: NVD
CVE-2026-2892 HIGH - 7.5

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated u...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7402 HIGH - 8.1

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Published: Apr 30, 2026
Source: NVD
CVE-2026-7399 HIGH - 8.1

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Published: Apr 30, 2026
Source: NVD
CVE-2025-14576 HIGH - 7.8

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service,...

Vendor: The Qt Company
Product: Qt
Published: Apr 30, 2026
Source: NVD
CVE-2024-13971 HIGH - 7.5

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Vendor: Lobster GmbH
Product: Lobster_pro
Published: Apr 30, 2026
Source: NVD