Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 5,541 - 5,560 of 13,511 CVEs
CVE-2026-41472 MEDIUM - 6.1

CyberPanel versions prior toΒ 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanH...

Vendor: usmannasir
Product: cyberpanel
Published: Apr 24, 2026
Source: NVD
CVE-2026-41263 MEDIUM - 3.7

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing side-channel vulnerability in Traefik's BasicAuth middleware that allows an attacker to enumerate valid usernames through response-time differences. The variable intended to ...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub
CVE-2026-6968 MEDIUM - 5.9

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked m...

Published: Apr 24, 2026
Source: NVD
CVE-2026-6967 MEDIUM - 5.9

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache, ...

Vendor: rust
Product: tough
Published: Apr 24, 2026
Source: NVD
CVE-2026-6966 MEDIUM - 5.3

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role meta...

Vendor: rust
Product: tough
Published: Apr 24, 2026
Source: NVD
CVE-2026-41426 MEDIUM - 6.1

pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by embedding malformed HTML or markdown link syntax in a user-controlled template placeholder such as the account dis...

Vendor: pretalx
Product: pretalx
Published: Apr 24, 2026
Source: NVD
CVE-2026-41425 MEDIUM - 5.4

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

Vendor: authlib
Product: authlib
Published: Apr 24, 2026
Source: NVD
CVE-2026-41244 MEDIUM - 4.7

Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), al...

Vendor: notamitgamer
Product: mojic
Published: Apr 24, 2026
Source: NVD
CVE-2026-41174 MEDIUM - 6.4

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetesCRD.allowCrossNamespace=false, Traefik correctly rejects...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub
CVE-2026-41418 MEDIUM - 5.3

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). When an invalid username/email is provided, the server responds immediately (~17ms average). When a v...

Vendor: RARgames
Product: 4gaBoards
Published: Apr 24, 2026
Source: NVD
CVE-2026-42044 MEDIUM - 6.5

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisib...

Vendor: axios
Product: axios
Published: Apr 24, 2026
Source: NVD
CVE-2026-42042 MEDIUM - 5.4

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truth...

Vendor: axios
Product: axios
Published: Apr 24, 2026
Source: NVD
CVE-2026-42041 MEDIUM - 4.8

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing the...

Vendor: axios
Product: axios
Published: Apr 24, 2026
Source: NVD
CVE-2026-42038 MEDIUM - 6.8

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy(...

Vendor: axios
Product: axios
Published: Apr 24, 2026
Source: NVD
CVE-2026-42037 MEDIUM - 5.3

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\r\n) sequences. An attacker wh...

Vendor: axios
Product: axios
Published: Apr 24, 2026
Source: NVD
CVE-2026-42036 MEDIUM - 5.3

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption...

Vendor: axios
Product: axios
Published: Apr 24, 2026
Source: NVD
CVE-2026-42034 MEDIUM - 5.3

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits....

Vendor: axios
Product: axios
Published: Apr 24, 2026
Source: NVD
CVE-2026-41411 MEDIUM - 6.6

Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the file...

Vendor: vim
Product: vim
Published: Apr 24, 2026
Source: NVD
CVE-2026-41079 MEDIUM - 4.3

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is c...

Vendor: OpenPrinting
Product: cups
Published: Apr 24, 2026
Source: NVD
CVE-2026-30368 MEDIUM - 5.4

A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.

Published: Apr 24, 2026
Source: NVD