Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
Showing 6,061 - 6,080 of 13,518 CVEs
CVE-2026-21728 HIGH - 7.5

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).

Vendor: Grafana
Product: Tempo
Published: Apr 24, 2026
Source: NVD
CVE-2026-5364 HIGH - 8.1

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attack...

Published: Apr 24, 2026
Source: NVD
CVE-2026-6947 HIGH - 7.5

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device.

Published: Apr 24, 2026
Source: NVD
CVE-2026-41485 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller ...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41324 HIGH - 7.5

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client....

Vendor: patrickjuchli
Product: basic-ftp
Published: Apr 24, 2026
Source: NVD
CVE-2026-41323 HIGH - 8.1

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service UR...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41068 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating the `URLPath` field. However, the ConfigMap context loader has the identical vulnerability — the ...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD
CVE-2026-41317 HIGH - 7.5

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to database and it is also accessible via GET method. The patch in commit ...

Vendor: frappe
Product: press
Published: Apr 24, 2026
Source: NVD
CVE-2026-41316 HIGH - 8.1

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other publi...

Vendor: ruby
Product: erb
Published: Apr 24, 2026
Source: NVD
CVE-2026-41309 HIGH - 8.2

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file siz...

Vendor: opensource-socialnetwork
Product: opensource-socialnetwork
Published: Apr 24, 2026
Source: NVD
CVE-2026-33317 HIGH - 8.7

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()` in `ta/pkcs11/src/object.c` can lead to out-of-bounds ...

Vendor: OP-TEE
Product: optee_os
Published: Apr 24, 2026
Source: NVD
CVE-2026-33208 HIGH - 8.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into a shell command string that is subsequently...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-33077 HIGH - 7.5

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-41325 HIGH - 8.8

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also possible to custom...

Vendor: getkirby
Product: kirby
Published: Apr 24, 2026
Source: NVD
CVE-2026-40623 HIGH - 8.1

A vulnerability inĀ SenseLiveĀ X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watc...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-39462 HIGH - 8.1

A vulnerability exists inĀ SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-35064 HIGH - 7.5

A vulnerability inĀ SenseLiveĀ X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and management interfaces without requiring credentials. Because discovery functions are exp...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-31952 HIGH - 7.6

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injection vulnerability in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain...

Vendor: xibosignage
Product: xibo-cms
Published: Apr 24, 2026
Source: NVD
CVE-2026-27841 HIGH - 8.1

A vulnerability inĀ SenseLiveĀ X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application does not enforce server-side validation of request origin or implement CSRF tokens, a malicious ex...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-41361 HIGH - 7.1

OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by crafting URLs targeting internal or non-routable IPv6 addresses to bypass SSRF protections.

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 23, 2026
Source: NVD