Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,804
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 5,161 - 5,180 of 13,495 CVEs
CVE-2026-40949 MEDIUM - 4.4

CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD
CVE-2026-3346 MEDIUM - 6.4

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess...

Published: Apr 30, 2026
Source: NVD
CVE-2026-3340 MEDIUM - 6.5

IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Published: Apr 30, 2026
Source: NVD
CVE-2026-33452 MEDIUM - 5.5

CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to β€˜blue screen’ the system.

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD
CVE-2026-33450 MEDIUM - 5.5

CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service.

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD
CVE-2026-28532 MEDIUM - 6.5

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer...

Vendor: FRRouting
Product: frr
Published: Apr 30, 2026
Source: NVD
CVE-2026-7429 MEDIUM - 4.6

SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can exploit improper output enc...

Published: Apr 30, 2026
Source: NVD
CVE-2026-40603 MEDIUM - 6.5

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that returns a project's report data to any authenticated member of the same team, even when that user does...

Vendor: chartbrew
Product: chartbrew
Published: Apr 30, 2026
Source: NVD
CVE-2026-35514 MEDIUM - 6.5

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token, authentication header, or session. Any unauthenticated attacker can call this endpoint ...

Vendor: chartbrew
Product: chartbrew
Published: Apr 30, 2026
Source: NVD
CVE-2026-32148 MEDIUM - 5.9

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in the mix.lock file to ensure reproducible and integrity-checked builds. However, Hex.R...

Vendor: hexpm
Product: hex
Published: Apr 30, 2026
Source: NVD
CVE-2026-42191 MEDIUM - 6.5

OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTelemetry.Exporter.OpenTelemetryProtocol silently fell back to Path.GetTempPath() when OTEL_DOTNET_EXPERIMENTAL_OTLP_RETRY=disk was set ...

Vendor: nuget
Product: OpenTelemetry.Exporter.OpenTelemetryProtocol
Published: Apr 30, 2026
Source: GitHub
CVE-2026-3833 MEDIUM - 6.5

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting ...

Vendor: gnu
Product: gnutls
Published: Apr 30, 2026
Source: NVD
CVE-2026-36766 MEDIUM - 5.4

Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36763 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36761 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the msgContent parameter.

Published: Apr 30, 2026
Source: NVD
CVE-2026-42032 MEDIUM - 9.1

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system information This vulnerabilit...

Vendor: pip
Product: ckan
Published: Apr 30, 2026
Source: GitHub
CVE-2026-41654 MEDIUM - 8.1

Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-...

Vendor: pip
Product: weblate
Published: Apr 30, 2026
Source: GitHub
CVE-2026-41519 MEDIUM - 4.2

Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has ...

Vendor: pip
Product: weblate
Published: Apr 30, 2026
Source: GitHub
CVE-2026-36764 MEDIUM - 5.0

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36757 MEDIUM - 4.3

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD