Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,767
Quick preset (or use dates below)
Clear Filters
Showing 6,001 - 6,020 of 13,893 CVEs
CVE-2026-22005 MEDIUM - 4.9

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise My...

Vendor: oracle
Product: mysql_server
Published: Apr 21, 2026
Source: NVD
CVE-2026-22004 MEDIUM - 4.9

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server....

Vendor: oracle
Product: mysql_server
Published: Apr 21, 2026
Source: NVD
CVE-2026-22003 MEDIUM - 6.0

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u481 and 8u481-b50; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows low privileged ...

Vendor: oracle
Product: graalvm
Published: Apr 21, 2026
Source: NVD
CVE-2026-22002 MEDIUM - 4.9

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise My...

Vendor: oracle
Product: mysql_server
Published: Apr 21, 2026
Source: NVD
CVE-2026-21999 MEDIUM - 5.3

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise XML Database. Successful attacks require human interaction ...

Published: Apr 21, 2026
Source: NVD
CVE-2026-21998 MEDIUM - 4.9

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise My...

Vendor: oracle
Product: mysql_server
Published: Apr 21, 2026
Source: NVD
CVE-2026-41067 MEDIUM - 6.1

Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected into inline <script> tags via the define:vars directive. HTML parsers close <script> elements...

Vendor: npm
Product: astro
Published: Apr 21, 2026
Source: GitHub
CVE-2026-41320 MEDIUM - 6.5

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. Versions 15.54.0 a...

Vendor: frappe
Product: hrms
Published: Apr 21, 2026
Source: NVD
CVE-2026-40908 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enabling version fingerprinting against known CVEs), d...

Vendor: WWBN
Product: AVideo
Published: Apr 21, 2026
Source: NVD
CVE-2026-40907 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming permission to retrieve other users' live res...

Vendor: WWBN
Product: AVideo
Published: Apr 21, 2026
Source: NVD
CVE-2026-40889 MEDIUM - 6.5

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workarounds are available.

Vendor: frappe
Product: hrms
Published: Apr 21, 2026
Source: NVD
CVE-2026-40888 MEDIUM - 6.5

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known workarounds are availabl...

Vendor: frappe
Product: hrms
Published: Apr 21, 2026
Source: NVD
CVE-2026-33812 MEDIUM - 6.1

Parsing a malicious font file can cause excessive memory allocation.

Vendor: golang.org/x/image
Product: golang.org/x/image/font/sfnt
Published: Apr 21, 2026
Source: NVD
CVE-2026-6744 MEDIUM - 6.3

A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted earl...

Published: Apr 21, 2026
Source: NVD
CVE-2026-22751 MEDIUM - 4.8

Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0...

Vendor: Spring
Product: Spring Security
Published: Apr 21, 2026
Source: NVD
CVE-2026-40343 MEDIUM - 5.8

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue ...

Vendor: go
Product: github.com/free5gc/udr
Published: Apr 21, 2026
Source: GitHub
CVE-2026-41194 MEDIUM - 5.4

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /mailbox/oauth-disconnect/{id}/{in_out}/{provider}`. It removes stored OAuth metadata from the mailbox and then redirects. Because it is a GET route, no ...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-40608 MEDIUM - 6.2

Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/state, /api/restore, and /api/history-svg) that process incoming requests by accumulating the entire request body into a J...

Vendor: DayuanJiang
Product: next-ai-draw-io
Published: Apr 21, 2026
Source: NVD
CVE-2026-40606 MEDIUM - 4.8

mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmproxy 12.2.1 and below, the builtin LDAP proxy authentication does not correctly sanitize the username when querying the LDAP serv...

Vendor: mitmproxy
Product: mitmproxy
Published: Apr 21, 2026
Source: NVD
CVE-2026-40604 MEDIUM - 4.4

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any proc...

Vendor: craigjbass
Product: clearancekit
Published: Apr 21, 2026
Source: NVD