Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,810
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 5,441 - 5,460 of 13,509 CVEs
CVE-2026-7143 MEDIUM - 6.3

A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and migh...

Published: Apr 27, 2026
Source: NVD
CVE-2026-25908 MEDIUM - 6.7

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulnerability in the AWCC. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

Vendor: Dell
Product: Alienware Command Center (AWCC)
Published: Apr 27, 2026
Source: NVD
CVE-2026-7142 MEDIUM - 6.3

A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of the component API Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has b...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7141 MEDIUM - 5.6

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource. It is possible to initiate the attack remotely. The attack i...

Vendor: vllm
Product: vllm
Published: Apr 27, 2026
Source: NVD
CVE-2026-38936 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

Published: Apr 27, 2026
Source: NVD
CVE-2026-38935 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter

Published: Apr 27, 2026
Source: NVD
CVE-2026-30462 MEDIUM - 4.3

A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal.

Published: Apr 27, 2026
Source: NVD
CVE-2026-30346 MEDIUM - 4.3

An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7135 MEDIUM - 5.3

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attac...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7134 MEDIUM - 4.7

A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit is publicly available and might be ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-41467 MEDIUM - 5.4

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and HTM file uploads. Authenticated attackers can upload HTML files containing arbitrary JavaScript through the im...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41466 MEDIUM - 5.4

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by only detecting specific patterns while returning unsanitized strings without output encoding. Attackers can...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41465 MEDIUM - 6.5

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequence...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41464 MEDIUM - 6.5

ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data belonging to other users including password hashes and API keys. Attackers can bypass access con...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-7133 MEDIUM - 4.7

A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7132 MEDIUM - 5.3

A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-40514 MEDIUM - 5.9

SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possibl...

Vendor: SmarterTools Inc.
Product: SmarterMail
Published: Apr 27, 2026
Source: NVD
CVE-2026-7129 MEDIUM - 4.3

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit...

Published: Apr 27, 2026
Source: NVD
CVE-2026-41081 MEDIUM - 6.5

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTranspo...

Vendor: Apache Software Foundation
Product: Apache Storm Client
Published: Apr 27, 2026
Source: NVD
CVE-2026-40557 MEDIUM - 4.8

Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description:  In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it i...

Vendor: Apache Software Foundation
Product: Apache Storm Prometheus Reporter
Published: Apr 27, 2026
Source: NVD