Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,800
Quick preset (or use dates below)
Clear Filters
Showing 5,801 - 5,820 of 13,892 CVEs
CVE-2025-0186 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to...

Vendor: gitlab
Product: gitlab
Published: Apr 22, 2026
Source: NVD
CVE-2026-30139 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.

Published: Apr 22, 2026
Source: NVD
CVE-2025-58922 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affects Avada: from n/a before 7.13.2.

Vendor: ThemeFusion
Product: Avada
Published: Apr 22, 2026
Source: NVD
CVE-2024-58344 MEDIUM - 6.4

Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript code through the Forum Name field in dashboard settings. Attackers with admin privileges can store JavaScript payloads in the Forum Name field that exec...

Vendor: 94Cb
Product: Carbon Forum
Published: Apr 22, 2026
Source: NVD
CVE-2018-25271 MEDIUM - 6.2

Textpad 8.1.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long buffer string through the Run command interface. Attackers can paste a 5000-byte payload into the Command field via Tools > Run to trigger a buffer overfl...

Vendor: Textpad
Product: Textpad
Published: Apr 22, 2026
Source: NVD
CVE-2018-25269 MEDIUM - 6.1

ICEWARP 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that execute in the client when the ...

Vendor: icewarp
Product: ICEWARP Client
Published: Apr 22, 2026
Source: NVD
CVE-2018-25267 MEDIUM - 6.2

UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attackers can craft a malicious filename string with 304 bytes of data followed by SEH record overwrite value...

Vendor: Ultraiso
Product: UltraISO
Published: Apr 22, 2026
Source: NVD
CVE-2018-25266 MEDIUM - 6.2

Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to crash the application by supplying an excessively large string. Attackers can generate a file containing a massive buffer of repeated characters and paste it into the unavailable ...

Vendor: Angryip
Product: Angry IP Scanner
Published: Apr 22, 2026
Source: NVD
CVE-2018-25262 MEDIUM - 6.2

Angry IP Scanner for Linux 3.5.3 contains a denial of service vulnerability that allows local attackers to crash the application by supplying malformed input to the port selection field. Attackers can craft a malicious string containing buffer overflow patterns and paste it into the Preferences Port...

Vendor: Angryip
Product: Angry IP Scanner for Linux
Published: Apr 22, 2026
Source: NVD
CVE-2026-6862 MEDIUM - 5.5

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) device path node header. A local user could exploit this vul...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6861 MEDIUM - 6.1

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denia...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6355 MEDIUM - 6.5

A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configurati...

Published: Apr 22, 2026
Source: NVD
CVE-2026-33611 MEDIUM - 6.5

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.

Vendor: PowerDNS
Product: Authoritative
Published: Apr 22, 2026
Source: NVD
CVE-2026-33610 MEDIUM - 5.9

A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request to it.

Vendor: PowerDNS
Product: Authoritative
Published: Apr 22, 2026
Source: NVD
CVE-2026-33609 MEDIUM - 5.3

Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

Vendor: PowerDNS
Product: Authoritative
Published: Apr 22, 2026
Source: NVD
CVE-2026-33602 MEDIUM - 6.5

A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service.

Vendor: PowerDNS
Product: DNSdist
Published: Apr 22, 2026
Source: NVD
CVE-2026-33598 MEDIUM - 4.8

A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.

Vendor: PowerDNS
Product: DNSdist
Published: Apr 22, 2026
Source: NVD
CVE-2026-33595 MEDIUM - 5.3

A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.

Vendor: PowerDNS
Product: DNSdist
Published: Apr 22, 2026
Source: NVD
CVE-2026-33594 MEDIUM - 5.3

A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection.

Vendor: PowerDNS
Product: DNSdist
Published: Apr 22, 2026
Source: NVD
CVE-2026-33254 MEDIUM - 5.3

An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default.

Vendor: PowerDNS
Product: DNSdist
Published: Apr 22, 2026
Source: NVD