Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
Showing 5,501 - 5,520 of 13,362 CVEs
CVE-2026-36958 HIGH - 7.5

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the ro...

Vendor: u-speed
Product: n300_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-36957 HIGH - 7.5

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffer...

Vendor: dbitnet
Product: dbit_n300_t1_pro_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-36956 HIGH - 8.8

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An a...

Vendor: dbitnet
Product: dbit_n300_t1_pro_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-7246 HIGH - 7.2

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

Vendor: palletsprojects
Product: click
Published: Apr 30, 2026
Source: NVD
CVE-2026-2892 HIGH - 7.5

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated u...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7402 HIGH - 8.1

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Published: Apr 30, 2026
Source: NVD
CVE-2026-7399 HIGH - 8.1

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Published: Apr 30, 2026
Source: NVD
CVE-2025-14576 HIGH - 7.8

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service,...

Vendor: The Qt Company
Product: Qt
Published: Apr 30, 2026
Source: NVD
CVE-2024-13971 HIGH - 7.5

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Vendor: Lobster GmbH
Product: Lobster_pro
Published: Apr 30, 2026
Source: NVD
CVE-2026-41882 HIGH - 7.4

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Apr 30, 2026
Source: NVD
CVE-2026-31693 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary. However, some of these places were missing the necessary re...

Vendor: Linux
Product: Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-31787 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. When userspace does a partial munmap() on a privcmd mapping, the kernel splits the VMA via __split_vma...

Vendor: Linux
Product: Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-31786 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor a string. The first causes a buffer overflow as sprintf in buildid_show will read and ...

Vendor: Linux
Product: Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-42800 HIGH - 7.4

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

Vendor: ASR
Product: Lapwing_Linux
Published: Apr 30, 2026
Source: NVD
CVE-2026-42799 HIGH - 7.4

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

Vendor: ASR
Product: Kestrel
Published: Apr 30, 2026
Source: NVD
CVE-2026-42512 HIGH - 7.3

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to o...

Vendor: FreeBSD
Product: FreeBSD
Published: Apr 30, 2026
Source: NVD
CVE-2026-39457 HIGH - 7.8

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate lar...

Vendor: FreeBSD
Product: FreeBSD
Published: Apr 30, 2026
Source: NVD
CVE-2026-22070 HIGH - 7.1

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Vendor: OPPO
Product: ColorOS Assistant
Published: Apr 30, 2026
Source: NVD
CVE-2026-7164 HIGH - 7.5

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent...

Vendor: freebsd
Product: freebsd
Published: Apr 30, 2026
Source: NVD
CVE-2026-7270 HIGH - 7.3

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

Vendor: freebsd
Product: freebsd
Published: Apr 30, 2026
Source: NVD