Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,758
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,041 - 5,060 of 12,590 CVEs
CVE-2026-41882 HIGH - 7.4

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Apr 30, 2026
Source: NVD
CVE-2026-31693 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary. However, some of these places were missing the necessary re...

Vendor: Linux
Product: Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-31787 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. When userspace does a partial munmap() on a privcmd mapping, the kernel splits the VMA via __split_vma...

Vendor: Linux
Product: Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-31786 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor a string. The first causes a buffer overflow as sprintf in buildid_show will read and ...

Vendor: Linux
Product: Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-42800 HIGH - 7.4

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

Vendor: ASR
Product: Lapwing_Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-42799 HIGH - 7.4

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

Vendor: ASR
Product: Kestrel
Published: Apr 30, 2026
Source: NVD
CVE-2026-42512 HIGH - 7.3

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to o...

Vendor: FreeBSD
Product: FreeBSD
Published: Apr 30, 2026
Source: NVD
CVE-2026-39457 HIGH - 7.8

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate lar...

Vendor: FreeBSD
Product: FreeBSD
Published: Apr 30, 2026
Source: NVD
CVE-2026-22070 HIGH - 7.1

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Vendor: OPPO
Product: ColorOS Assistant
Published: Apr 30, 2026
Source: NVD
CVE-2026-7164 HIGH - 7.5

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent...

Vendor: freebsd
Product: freebsd
Published: Apr 30, 2026
Source: NVD
CVE-2026-7270 HIGH - 7.3

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

Vendor: freebsd
Product: freebsd
Published: Apr 30, 2026
Source: NVD
CVE-2026-5402 HIGH - 8.8

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-42511 HIGH - 7.3

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhcl...

Vendor: FreeBSD
Product: FreeBSD
Published: Apr 30, 2026
Source: NVD
CVE-2024-39847 HIGH - 7.5

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Vendor: 4D
Product: 4D Server
Published: Apr 30, 2026
Source: NVD
CVE-2025-13030 HIGH - 7.1

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary code execution since this endpoint lacks authentication protection and proper sanitisation of file nam...

Vendor: pylixm
Product: django-mdeditor
Published: Apr 30, 2026
Source: NVD
CVE-2026-7470 HIGH - 8.8

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and m...

Vendor: tenda
Product: 4g300_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-7468 HIGH - 7.3

A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been d...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7446 HIGH - 7.3

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command in...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7443 HIGH - 7.3

A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument Request can lead to os command injection. The attack may be launched r...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7420 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile results in buffer overflow. The attack can be executed remotely. The exploit has been released to the pu...

Published: Apr 29, 2026
Source: NVD