Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,861 - 5,880 of 12,679 CVEs
CVE-2026-6596 HIGH - 7.3

A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component API Endpoint. The manipulation results in unrestricted upload. It is possible to launch the attack re...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6595 HIGH - 7.3

A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of the component HTTP GET Parameter Handler. The manipulation of the argument bus_id leads to sql injecti...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6594 HIGH - 7.3

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The ve...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6582 HIGH - 7.3

A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_dbs.py of the component Vector Database Management Endpoint. Executing a manipulation can lead to missing authentication. The attack...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6581 HIGH - 8.8

A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now pu...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6580 HIGH - 7.3

A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipulation of the argument key leads to use of hard-coded cryptographic key . The attack may be launched...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6577 HIGH - 7.3

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly ava...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6574 HIGH - 7.3

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The ex...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6569 HIGH - 7.3

A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The ven...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6568 HIGH - 7.3

A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated remo...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6563 HIGH - 8.8

A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to th...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6562 HIGH - 7.3

A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a manipulation of the argument keyword can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. ...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6560 HIGH - 8.8

A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_BasicSSID of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly...

Published: Apr 19, 2026
Source: NVD
CVE-2026-32228 HIGH - 7.5

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 18, 2026
Source: NVD
CVE-2026-30912 HIGH - 7.5

In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 18, 2026
Source: NVD
CVE-2026-30898 HIGH - 8.8

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own DAGs have adopted this incorrect advice...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 18, 2026
Source: NVD
CVE-2026-6518 HIGH - 8.8

The CMP โ€“ Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_...

Published: Apr 18, 2026
Source: NVD
CVE-2026-40487 HIGH - 8.9

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then served by nginx with a C...

Vendor: gitroomhq
Product: postiz-app
Published: Apr 18, 2026
Source: NVD
CVE-2026-40350 HIGH - 8.8

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator account. This happens because the rout...

Vendor: leepeuker
Product: movary
Published: Apr 18, 2026
Source: NVD
CVE-2026-35465 HIGH - 7.5

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the Client's virtual machine (sd-app) by exploiting improper ...

Vendor: freedomofpress
Product: securedrop-client
Published: Apr 18, 2026
Source: NVD