Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 5,921 - 5,940 of 12,679 CVEs
CVE-2026-23778 HIGH - 7.2

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with r...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-23775 HIGH - 7.6

Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with remote access cou...

Vendor: Dell
Product: PowerProtect Data Domain appliances
Published: Apr 17, 2026
Source: NVD
CVE-2025-36568 HIGH - 7.8

Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an insufficiently protected credentials vulnerability. A low privileged attacker with local...

Vendor: Dell
Product: PowerProtect Data Domain BoostFS
Published: Apr 17, 2026
Source: NVD
CVE-2026-33392 HIGH - 7.2

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

Vendor: JetBrains
Product: YouTrack
Published: Apr 17, 2026
Source: NVD
CVE-2026-23853 HIGH - 8.4

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An unauthenticated attacker...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-4659 HIGH - 7.5

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ...

Published: Apr 17, 2026
Source: NVD
CVE-2026-6421 HIGH - 7.0

A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It is indicated that the...

Published: Apr 17, 2026
Source: NVD
CVE-2026-21719 HIGH - 7.2

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command.

Vendor: CubeCart Limited
Product: CubeCart
Published: Apr 17, 2026
Source: NVD
CVE-2026-5807 HIGH - 7.5

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot. This prevents legitimate operators from completing these workflows. This vulnerability,...

Vendor: go
Product: github.com/hashicorp/vault
Published: Apr 17, 2026
Source: NVD
CVE-2026-4525 HIGH - 7.5

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.

Vendor: go
Product: github.com/hashicorp/vault
Published: Apr 17, 2026
Source: NVD
CVE-2026-3605 HIGH - 8.1

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data...

Vendor: go
Product: github.com/hashicorp/vault
Published: Apr 17, 2026
Source: NVD
CVE-2026-5231 HIGH - 7.2

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output escaping. The plugin's referral parser copies the raw utm_source ...

Published: Apr 17, 2026
Source: NVD
CVE-2026-22734 HIGH - 8.6

Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor e...

Vendor: Cloud Foundry
Product: UUA
Published: Apr 17, 2026
Source: NVD
CVE-2026-40318 HIGH - 8.5

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequen...

Vendor: siyuan-note
Product: siyuan
Published: Apr 16, 2026
Source: NVD
CVE-2026-40897 HIGH - 8.8

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs ...

Vendor: npm
Product: mathjs
Published: Apr 16, 2026
Source: GitHub
CVE-2026-41113 HIGH - 8.1

sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.

Vendor: sagredo
Product: qmail
Published: Apr 16, 2026
Source: NVD

My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX endpoint, registered for unauthenticated users, passes user-supplied arguments through parse_str() without validation, allowing injection of arbitrary parameters including a site...

Vendor: joedolson
Product: my-calendar
Published: Apr 16, 2026
Source: NVD
CVE-2026-40170 HIGH - 7.5

ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transpo...

Vendor: ngtcp2
Product: ngtcp2
Published: Apr 16, 2026
Source: NVD

mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the HTTP transport concatenates request body chunks into a string with no size limit. Although a maxMessageSize configuration value exists, it is never enfo...

Vendor: QuantGeekDev
Product: mcp-framework
Published: Apr 16, 2026
Source: NVD

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in ...

Vendor: moby
Product: spdystream
Published: Apr 16, 2026
Source: NVD