Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
Showing 5,441 - 5,460 of 13,878 CVEs
CVE-2026-41465 MEDIUM - 6.5

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequences before constructing file paths. Authenticated attackers can inject directory traversal sequence...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-41464 MEDIUM - 6.5

ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data belonging to other users including password hashes and API keys. Attackers can bypass access con...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-7133 MEDIUM - 4.7

A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7132 MEDIUM - 5.3

A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-40514 MEDIUM - 5.9

SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possibl...

Vendor: SmarterTools Inc.
Product: SmarterMail
Published: Apr 27, 2026
Source: NVD
CVE-2026-7129 MEDIUM - 4.3

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit...

Published: Apr 27, 2026
Source: NVD
CVE-2026-41081 MEDIUM - 6.5

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTranspo...

Vendor: Apache Software Foundation
Product: Apache Storm Client
Published: Apr 27, 2026
Source: NVD
CVE-2026-40557 MEDIUM - 4.8

Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description:  In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it i...

Vendor: Apache Software Foundation
Product: Apache Storm Prometheus Reporter
Published: Apr 27, 2026
Source: NVD
CVE-2026-7118 MEDIUM - 6.3

A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation of the argument id/token leads to sql injection. The attack is possible to be carried out remotely. The exploit ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7117 MEDIUM - 6.3

A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has been made available to...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7116 MEDIUM - 4.3

A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-5942 MEDIUM - 5.5

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-5939 MEDIUM - 5.5

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-5938 MEDIUM - 5.5

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-5937 MEDIUM - 5.5

Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.

Vendor: foxit
Product: pdf_editor
Published: Apr 27, 2026
Source: NVD
CVE-2026-42410 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.

Vendor: CodexThemes
Product: TheGem Theme Elements (for Elementor)
Published: Apr 27, 2026
Source: NVD
CVE-2026-7115 MEDIUM - 6.3

A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7114 MEDIUM - 6.3

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7113 MEDIUM - 5.6

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be laun...

Published: Apr 27, 2026
Source: NVD
CVE-2026-27172 MEDIUM - 6.3

The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Consul KV store and passed them to ObjectInputStream.readObject() without configuring an ObjectInputFilt...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Apr 27, 2026
Source: NVD