Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
Showing 5,281 - 5,300 of 13,876 CVEs
CVE-2026-26204 MEDIUM - 4.4

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 byte before the start of the buffer allocated by strdup. Due ...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-7393 MEDIUM - 4.7

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be car...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7392 MEDIUM - 6.3

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been dis...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7391 MEDIUM - 6.3

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publishe...

Published: Apr 29, 2026
Source: NVD
CVE-2026-6915 MEDIUM - 6.3

An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.

Vendor: mongodb
Product: mongodb
Published: Apr 29, 2026
Source: NVD
CVE-2026-6914 MEDIUM - 6.5

Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior to...

Vendor: mongodb
Product: mongodb
Published: Apr 29, 2026
Source: NVD
CVE-2026-0206 MEDIUM - 4.9

A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

Vendor: sonicwall
Product: sonicos
Published: Apr 29, 2026
Source: NVD
CVE-2026-0205 MEDIUM - 6.8

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

Vendor: sonicwall
Product: sonicos
Published: Apr 29, 2026
Source: NVD
CVE-2026-7388 MEDIUM - 4.7

A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File Handler. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been mad...

Published: Apr 29, 2026
Source: NVD
CVE-2026-40230 MEDIUM - 5.4

Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0.

Vendor: helpyio
Product: helpy
Published: Apr 29, 2026
Source: NVD
CVE-2026-40229 MEDIUM - 5.4

Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notifica...

Vendor: helpyio
Product: helpy
Published: Apr 29, 2026
Source: NVD
CVE-2026-38993 MEDIUM - 6.5

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

Published: Apr 29, 2026
Source: NVD
CVE-2025-56537 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.

Vendor: opennebula
Product: opennebula
Published: Apr 29, 2026
Source: NVD
CVE-2025-56536 MEDIUM - 6.1

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.

Vendor: opennebula
Product: opennebula
Published: Apr 29, 2026
Source: NVD
CVE-2025-56535 MEDIUM - 6.1

A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.

Vendor: opennebula
Product: opennebula
Published: Apr 29, 2026
Source: NVD
CVE-2025-56534 MEDIUM - 6.1

A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Vendor: opennebula
Product: opennebula
Published: Apr 29, 2026
Source: NVD
CVE-2026-25852 MEDIUM - 6.7

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212.

Vendor: Acronis
Product: Acronis DeviceLock DLP
Published: Apr 29, 2026
Source: NVD
CVE-2026-42525 MEDIUM - 4.3

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Vendor: Jenkins Project
Product: Jenkins Microsoft Entra ID (previously Azure AD) Plugin
Published: Apr 29, 2026
Source: NVD
CVE-2026-42522 MEDIUM - 4.3

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.

Vendor: Jenkins Project
Product: Jenkins GitHub Branch Source Plugin
Published: Apr 29, 2026
Source: NVD
CVE-2026-42521 MEDIUM - 6.5

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure ...

Vendor: Jenkins Project
Product: Jenkins Matrix Authorization Strategy Plugin
Published: Apr 29, 2026
Source: NVD