Total CVEs

140,303

Critical Severity

3,711

High Severity

13,353

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
Showing 5,261 - 5,280 of 13,353 CVEs
CVE-2026-42079 HIGH - 8.6

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.

Vendor: icip-cas
Product: PPTAgent
Published: May 04, 2026
Source: NVD
CVE-2026-42075 HIGH - 8.1

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enablin...

Vendor: EvoMap
Product: evolver
Published: May 04, 2026
Source: NVD
CVE-2026-37461 HIGH - 7.5

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Vendor: osrg
Product: gobgp
Published: May 04, 2026
Source: NVD
CVE-2026-29514 HIGH - 8.8

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the env...

Vendor: netbox-community
Product: netbox
Published: May 04, 2026
Source: NVD
CVE-2026-24082 HIGH - 7.8

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47408 HIGH - 7.8

Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47407 HIGH - 7.8

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2025-47405 HIGH - 7.8

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: May 04, 2026
Source: NVD
CVE-2026-40563 HIGH - 7.1

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data ...

Vendor: Apache Software Foundation
Product: Apache Atlas
Published: May 04, 2026
Source: NVD
CVE-2026-36365 HIGH - 7.8

An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp

Published: May 04, 2026
Source: NVD
CVE-2026-29169 HIGH - 7.5

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlie...

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-23918 HIGH - 8.8

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-6266 HIGH - 8.3

A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a v...

Published: May 04, 2026
Source: NVD
CVE-2025-70069 HIGH - 7.5

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method

Published: May 04, 2026
Source: NVD
CVE-2025-58074 HIGH - 8.8

A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges.

Vendor: Gen Digital
Product: Norton Secure VPN
Published: May 04, 2026
Source: NVD
CVE-2026-34059 HIGH - 7.5

Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-24072 HIGH - 8.8

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: May 04, 2026
Source: NVD
CVE-2026-3120 HIGH - 7.2

Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.

Published: May 04, 2026
Source: NVD
CVE-2026-7750 HIGH - 8.8

A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument mac_address results in buffer overflow. The attack may be launched remot...

Published: May 04, 2026
Source: NVD
CVE-2026-7749 HIGH - 8.8

A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument priDns leads to buffer overflow. The attack may be initiated remotely. The ex...

Published: May 04, 2026
Source: NVD