Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,698
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,041 - 6,060 of 12,679 CVEs
CVE-2026-30778 HIGH - 7.5

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache SkyWalking
Published: Apr 15, 2026
Source: NVD

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Ja...

Vendor: maven
Product: org.bouncycastle:bcpg-jdk12
Published: Apr 15, 2026
Source: NVD
CVE-2024-33618 HIGH - 7.5

Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk space via network interface.

Vendor: Bosch
Product: BVMS, BVMS Viewer, Bosch DIVAR IP all-in-one 7000 R3, Bosch DIVAR IP 7000 R2, Bosch DIVAR IP all-in-one 5000, Bosch DIVAR IP all-in-one 7000, DIVAR IP all-in-one 4000, DIVAR IP all-in-one 6000
Published: Apr 15, 2026
Source: NVD
CVE-2026-5694 HIGH - 7.2

The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'loan-period' parameters in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauth...

Published: Apr 15, 2026
Source: NVD
CVE-2026-5617 HIGH - 8.8

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-si...

Published: Apr 15, 2026
Source: NVD
CVE-2026-3643 HIGH - 7.2

The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 3.0.3. The plugin registers REST API endpoints at `/otm-ac/v1/update-widget-options` and `/otm-ac/v1/update-app-config` with the `permission_callback` set to `__ret...

Published: Apr 15, 2026
Source: NVD
CVE-2025-40899 HIGH - 8.9

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Assets...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: Apr 15, 2026
Source: NVD
CVE-2025-40897 HIGH - 8.1

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality can perform administ...

Vendor: Nozomi Networks
Product: Guardian, CMC
Published: Apr 15, 2026
Source: NVD
CVE-2026-5088 HIGH - 7.5

Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt. If those modules are unavailable, it will simp...

Published: Apr 15, 2026
Source: NVD
CVE-2026-40719 HIGH - 7.5

Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.

Vendor: MaraDNS
Product: MaraDNS
Published: Apr 15, 2026
Source: NVD
CVE-2026-5397 HIGH - 7.8

It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL is...

Published: Apr 15, 2026
Source: NVD
CVE-2026-33806 HIGH - 7.5

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= ...

Vendor: fastify
Product: fastify
Published: Apr 15, 2026
Source: NVD
CVE-2026-2834 HIGH - 7.2

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ parameter in all versions up to, and including, 3.32.3 due to insufficient input sanitization and output escaping. This makes it possible for una...

Published: Apr 15, 2026
Source: NVD
CVE-2025-54550 HIGH - 8.1

The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. Since the UI users are already highly tru...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 15, 2026
Source: NVD
CVE-2026-40688 HIGH - 7.2

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

Vendor: Fortinet
Product: FortiWeb
Published: Apr 14, 2026
Source: NVD
CVE-2026-39387 HIGH - 7.2

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to ...

Vendor: BoidCMS
Product: BoidCMS
Published: Apr 14, 2026
Source: NVD
CVE-2026-35589 HIGH - 8.0

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The original fix changed the binding from 0.0.0....

Vendor: HKUDS
Product: nanobot
Published: Apr 14, 2026
Source: NVD
CVE-2026-33023 HIGH - 7.8

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path manually frees the sixel_frame_t object and its...

Vendor: saitoha
Product: libsixel
Published: Apr 14, 2026
Source: NVD
CVE-2026-33021 HIGH - 7.3

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer directly in frame->pixels without making a de...

Vendor: saitoha
Product: libsixel
Published: Apr 14, 2026
Source: NVD
CVE-2026-27298 HIGH - 7.8

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi...

Vendor: Adobe
Product: Adobe Framemaker
Published: Apr 14, 2026
Source: NVD