Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
Showing 6,081 - 6,100 of 13,893 CVEs
CVE-2026-4852 MEDIUM - 6.4

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment field in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it po...

Published: Apr 20, 2026
Source: NVD
CVE-2026-33431 MEDIUM - 6.5

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path to construct a local file path, which is subsequently o...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 20, 2026
Source: NVD
CVE-2026-29647 MEDIUM - 6.5

In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when mstateen0.IMSIC is cleared, potentially enabling cross-context information leakage or disruption of interrupt handling.

Published: Apr 20, 2026
Source: NVD
CVE-2026-6550 MEDIUM - 4.7

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decryp...

Vendor: pip
Product: aws-encryption-sdk
Published: Apr 20, 2026
Source: NVD
CVE-2026-6060 MEDIUM - 4.5

A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS:Ā  * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.3.X

Published: Apr 20, 2026
Source: NVD
CVE-2026-41389 MEDIUM - 5.8

OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosi...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 20, 2026
Source: NVD
CVE-2026-39112 MEDIUM - 5.4

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisitor...

Published: Apr 20, 2026
Source: NVD
CVE-2026-26399 MEDIUM - 5.3

A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it is stored in a global timer handle registry. After the functio...

Published: Apr 20, 2026
Source: NVD
CVE-2026-23758 MEDIUM - 5.4

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Cont...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23757 MEDIUM - 5.4

GFI HelpDesk before 4.99.10Ā contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaScript into the report title field when creating or editing a re...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23756 MEDIUM - 5.4

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can in...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23753 MEDIUM - 4.8

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An a...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-23752 MEDIUM - 4.8

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can inj...

Vendor: GFI Software
Product: HelpDesk
Published: Apr 20, 2026
Source: NVD
CVE-2026-40098 MEDIUM - 5.4

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the shared wishlist add-to-cart endpoint authorizes access with a public `sha...

Vendor: OpenMage
Product: magento-lts
Published: Apr 20, 2026
Source: NVD
CVE-2026-35154 MEDIUM - 6.3

Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could poten...

Vendor: Dell
Product: PowerProtect Data Domain appliances
Published: Apr 20, 2026
Source: NVD
CVE-2026-28684 MEDIUM - 6.6

python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when ...

Vendor: theskumar
Product: python-dotenv
Published: Apr 20, 2026
Source: NVD
CVE-2026-26951 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerab...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 20, 2026
Source: NVD
CVE-2026-26942 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command ...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 20, 2026
Source: NVD
CVE-2026-25525 MEDIUM - 4.9

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the Dataflow module in OpenMage LTS uses a weak blacklist filter (`str_replac...

Vendor: OpenMage
Product: magento-lts
Published: Apr 20, 2026
Source: NVD
CVE-2026-22761 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 20, 2026
Source: NVD