Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,746
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,201 - 5,220 of 12,590 CVEs
CVE-2026-3323 HIGH - 7.5

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7279 HIGH - 7.8

AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specific directory, resulting in arbitrary code execution with system privileges when the system loads the DLL.

Published: Apr 28, 2026
Source: NVD
CVE-2026-41636 HIGH - 7.5

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41605 HIGH - 7.3

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41604 HIGH - 8.2

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41603 HIGH - 7.4

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41602 HIGH - 7.5

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2025-48431 HIGH - 7.5

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift serve...

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-7247 HIGH - 7.2

A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The ex...

Vendor: dlink
Product: di-8100_firmware
Published: Apr 28, 2026
Source: NVD
CVE-2026-40978 HIGH - 8.8

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

Vendor: Spring
Product: Spring AI
Published: Apr 28, 2026
Source: NVD
CVE-2026-7237 HIGH - 7.3

A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold-mcp/src/server/index.ts of the component write-to-file Tool. The manipulation of the argument file_path results in path traversal. The attack may be l...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7234 HIGH - 7.3

A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit h...

Published: Apr 28, 2026
Source: NVD
CVE-2026-40967 HIGH - 8.6

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Affected versions: Spring AI: 1.0.0 -...

Vendor: Spring
Product: Spring AI
Published: Apr 28, 2026
Source: NVD
CVE-2026-7228 HIGH - 7.3

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has b...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7227 HIGH - 7.3

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login. The manipulation of the argument e-mail results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7226 HIGH - 7.3

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/ajax.php?action=login2. The manipulation of the argument e-mail leads to sql injection. Remote exploitation of the attack is possible. The exploit has ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7225 HIGH - 7.3

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function delete_menu of the file /admin/ajax.php?action=delete_menu. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit h...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7224 HIGH - 7.3

A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7223 HIGH - 7.3

A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request fo...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7221 HIGH - 7.3

A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch ...

Published: Apr 28, 2026
Source: NVD