Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,804
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 5,181 - 5,200 of 13,497 CVEs
CVE-2026-36764 MEDIUM - 5.0

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36757 MEDIUM - 4.3

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-38940 MEDIUM - 6.1

Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component

Published: Apr 30, 2026
Source: NVD
CVE-2026-38939 MEDIUM - 6.1

Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component

Published: Apr 30, 2026
Source: NVD
CVE-2026-36759 MEDIUM - 6.5

A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36758 MEDIUM - 4.3

A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36756 MEDIUM - 5.4

A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Published: Apr 30, 2026
Source: NVD
CVE-2026-7500 MEDIUM - 5.4

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` ...

Vendor: redhat
Product: build_of_keycloak
Published: Apr 30, 2026
Source: NVD
CVE-2026-7163 MEDIUM - 6.1

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hu...

Vendor: redhat
Product: multicluster_engine_for_kubernetes
Published: Apr 30, 2026
Source: NVD
CVE-2026-7382 MEDIUM - 6.5

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Published: Apr 30, 2026
Source: NVD
CVE-2026-5080 MEDIUM - 5.9

Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with the process id, the epoch time and calls to the built-in rand() function to return a number between 0 and 999-...

Vendor: perldancer
Product: dancer\
Published: Apr 30, 2026
Source: NVD
CVE-2026-1493 MEDIUM - 5.4

LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser. An attacker with ability to set a cookie can p...

Vendor: wolterskluwer
Product: lex_baza_dokumentow
Published: Apr 30, 2026
Source: NVD
CVE-2026-31692 MEDIUM - 5.5

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer network namespace when creating paired devices (veth, vxcan, netkit). This allows an unprivileged u...

Vendor: Linux
Product: Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-6498 MEDIUM - 5.3

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the ...

Published: Apr 30, 2026
Source: NVD
CVE-2026-41016 MEDIUM - 5.9

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete th...

Vendor: Apache Software Foundation
Product: Apache Airflow Providers SMTP
Published: Apr 30, 2026
Source: NVD
CVE-2026-6870 MEDIUM - 5.5

GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-6869 MEDIUM - 5.5

WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-6867 MEDIUM - 5.5

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-6538 MEDIUM - 5.5

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-6537 MEDIUM - 5.5

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD