Total CVEs

140,303

Critical Severity

3,711

High Severity

13,353

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
Showing 5,521 - 5,540 of 13,885 CVEs
CVE-2026-41572 MEDIUM - 5.3

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note ...

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-6994 MEDIUM - 6.3

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch n...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6993 MEDIUM - 5.3

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6991 MEDIUM - 6.3

A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6989 MEDIUM - 6.3

A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ma...

Vendor: tenda
Product: f453_firmware
Published: Apr 25, 2026
Source: NVD
CVE-2026-6985 MEDIUM - 5.3

A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument optlen causes infinite loop. The attack is possible to be carried out remotely. The ...

Vendor: cesanta
Product: mongoose
Published: Apr 25, 2026
Source: NVD
CVE-2026-6984 MEDIUM - 4.7

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The manipulation results in improper neutralization of special elements used in a template engine. The attack...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6983 MEDIUM - 4.7

A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is p...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6982 MEDIUM - 6.3

A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component API Page Sort Endpoint. Executing a manipulation of the argument pages can l...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6981 MEDIUM - 6.3

A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a manipulation results in server-side request forgery. The attack ma...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6979 MEDIUM - 6.3

A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6978 MEDIUM - 4.7

A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sqls results in sql injection. It is possible to launch the attack remotely. The exploit is now public ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-41481 MEDIUM - 6.5

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the default)....

Vendor: langchain-ai
Product: langchain-text-splitters
Published: Apr 24, 2026
Source: NVD
CVE-2026-41472 MEDIUM - 6.1

CyberPanel versions prior toΒ 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanH...

Vendor: usmannasir
Product: cyberpanel
Published: Apr 24, 2026
Source: NVD
CVE-2026-41263 MEDIUM - 3.7

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing side-channel vulnerability in Traefik's BasicAuth middleware that allows an attacker to enumerate valid usernames through response-time differences. The variable intended to ...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub
CVE-2026-6968 MEDIUM - 5.9

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked m...

Published: Apr 24, 2026
Source: NVD
CVE-2026-6967 MEDIUM - 5.9

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, ...

Vendor: rust
Product: tough
Published: Apr 24, 2026
Source: NVD
CVE-2026-6966 MEDIUM - 5.3

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role meta...

Vendor: rust
Product: tough
Published: Apr 24, 2026
Source: NVD
CVE-2026-41426 MEDIUM - 6.1

pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by embedding malformed HTML or markdown link syntax in a user-controlled template placeholder such as the account dis...

Vendor: pretalx
Product: pretalx
Published: Apr 24, 2026
Source: NVD
CVE-2026-41425 MEDIUM - 5.4

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

Vendor: authlib
Product: authlib
Published: Apr 24, 2026
Source: NVD