Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,804
Quick preset (or use dates below)
Clear Filters
Showing 5,361 - 5,380 of 13,878 CVEs
CVE-2026-41373 MEDIUM - 6.1

OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C_COMPILER via environment overrides. Attackers with approved host-exec requests ...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 28, 2026
Source: NVD
CVE-2026-24231 MEDIUM - 6.3

NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful ex...

Vendor: NVIDIA
Product: NemoClaw
Published: Apr 28, 2026
Source: NVD
CVE-2026-24204 MEDIUM - 6.5

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.

Vendor: NVIDIA
Product: FLARE SDK
Published: Apr 28, 2026
Source: NVD
CVE-2026-38948 MEDIUM - 5.4

Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.

Published: Apr 28, 2026
Source: NVD
CVE-2025-60887 MEDIUM - 5.3

An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under the cista::raw namespace are prone to reference tampering, wh...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7283 MEDIUM - 4.7

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expired. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7282 MEDIUM - 4.7

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is p...

Published: Apr 28, 2026
Source: NVD
CVE-2026-40968 MEDIUM - 4.2

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: Sp...

Vendor: Spring
Product: Spring gRPC
Published: Apr 28, 2026
Source: NVD
CVE-2026-6706 MEDIUM - 6.5

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.

Vendor: devolutions
Product: devolutions_server
Published: Apr 28, 2026
Source: NVD
CVE-2026-7309 MEDIUM - 4.3

A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulner...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7271 MEDIUM - 5.3

A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-agent-server. Performing a manipulation of the argument req.params results in path traversal. Remote ex...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7268 MEDIUM - 6.3

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?action=save_category. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. The exploit has been disclo...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7267 MEDIUM - 6.3

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7266 MEDIUM - 6.3

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.php?action=save_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7265 MEDIUM - 6.3

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit h...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7280 MEDIUM - 6.7

AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7264 MEDIUM - 6.3

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?action=get_cart_items. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been m...

Published: Apr 28, 2026
Source: NVD
CVE-2026-41607 MEDIUM - 6.5

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-41606 MEDIUM - 5.3

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Apr 28, 2026
Source: NVD
CVE-2026-40980 MEDIUM - 6.5

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

Vendor: Spring
Product: Spring AI
Published: Apr 28, 2026
Source: NVD