Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 5,521 - 5,540 of 13,509 CVEs
CVE-2026-7024 MEDIUM - 5.4

A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServlet.java of the component deleteFileServlet Endpoint. Executing a manipulation of the argument filenam...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7023 MEDIUM - 6.3

A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the component databaseTool. Performing a manipulation results in sql injection. The attack can be initia...

Vendor: coze
Product: coze_studio
Published: Apr 26, 2026
Source: NVD
CVE-2026-7020 MEDIUM - 5.6

A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. T...

Vendor: ollama
Product: ollama
Published: Apr 26, 2026
Source: NVD
CVE-2026-7018 MEDIUM - 5.6

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argu...

Published: Apr 26, 2026
Source: NVD
CVE-2026-42254 MEDIUM - 4.0

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

Vendor: Hickory Project
Product: Hickory DNS
Published: Apr 26, 2026
Source: NVD
CVE-2026-41572 MEDIUM - 5.3

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note ...

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-6994 MEDIUM - 6.3

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch n...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6993 MEDIUM - 5.3

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6991 MEDIUM - 6.3

A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6989 MEDIUM - 6.3

A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ma...

Vendor: tenda
Product: f453_firmware
Published: Apr 25, 2026
Source: NVD
CVE-2026-6985 MEDIUM - 5.3

A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument optlen causes infinite loop. The attack is possible to be carried out remotely. The ...

Vendor: cesanta
Product: mongoose
Published: Apr 25, 2026
Source: NVD
CVE-2026-6984 MEDIUM - 4.7

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The manipulation results in improper neutralization of special elements used in a template engine. The attack...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6983 MEDIUM - 4.7

A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is p...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6982 MEDIUM - 6.3

A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component API Page Sort Endpoint. Executing a manipulation of the argument pages can l...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6981 MEDIUM - 6.3

A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a manipulation results in server-side request forgery. The attack ma...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6979 MEDIUM - 6.3

A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6978 MEDIUM - 4.7

A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sqls results in sql injection. It is possible to launch the attack remotely. The exploit is now public ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-41481 MEDIUM - 6.5

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the default)....

Vendor: langchain-ai
Product: langchain-text-splitters
Published: Apr 24, 2026
Source: NVD
CVE-2026-41472 MEDIUM - 6.1

CyberPanel versions prior toΒ 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanH...

Vendor: usmannasir
Product: cyberpanel
Published: Apr 24, 2026
Source: NVD
CVE-2026-41263 MEDIUM - 3.7

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing side-channel vulnerability in Traefik's BasicAuth middleware that allows an attacker to enumerate valid usernames through response-time differences. The variable intended to ...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub