Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,780
Quick preset (or use dates below)
Clear Filters
Showing 6,121 - 6,140 of 13,900 CVEs
CVE-2026-6654 MEDIUM - 5.1

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.

Published: Apr 20, 2026
Source: NVD
CVE-2026-6628 MEDIUM - 6.3

A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query Viewer Component. This manipulation of the argument custom causes sql injection. The attack can be initiated remotely. The exploit has been published ...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6626 MEDIUM - 6.3

A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/Aggregate Handler. The manipulation results in improper neutralization of special elements in data query logic. It is possible to launch the attack rem...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6620 MEDIUM - 6.3

A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path traversal. The attack may be launched remotely. The exploit has been...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6618 MEDIUM - 6.3

A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-side request forgery. T...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6617 MEDIUM - 6.3

A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Performing a manipulation of the argument url results in server-s...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6616 MEDIUM - 6.3

A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/helper/webpage_extractor.py of the component WebScraperTool. Such manipulation leads to server-side request forger...

Published: Apr 20, 2026
Source: NVD
CVE-2026-41282 MEDIUM - 4.0

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

Vendor: ProjectDiscovery
Product: Nuclei
Published: Apr 20, 2026
Source: NVD
CVE-2026-6614 MEDIUM - 6.3

A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulation results in authorization bypass. The attack may be perfor...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6613 MEDIUM - 6.3

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of the file superagi/controllers/agent.py. The manipulation of the argument agent_id leads to authorization bypass. The attack is possible to be carried o...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6612 MEDIUM - 6.3

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/agent_execution.py of the component Agent Execution Endpoint. Executing a manipulation of the argument agent_execution_id ...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6609 MEDIUM - 6.3

A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. T...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6608 MEDIUM - 5.3

A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fix...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6607 MEDIUM - 5.3

A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate of the component Worker API Endpoint. The manipulation leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6601 MEDIUM - 4.3

A vulnerability has been found in Lagom WHMCS Template up to 2.4.2. This impacts an unknown function of the component Datatables. The manipulation leads to resource consumption. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor wa...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6599 MEDIUM - 6.3

A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v1/mcp_projects.py of the component Model Context Protocol Configuration API. Performing a manipulation of the argument X-...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6598 MEDIUM - 4.3

A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the component Project Creation Endpoint. Such manipulation of the argument auth_settin...

Published: Apr 20, 2026
Source: NVD
CVE-2026-32964 MEDIUM - 6.5

SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration.

Vendor: silex technology, Inc.
Product: SD-330AC, AMC Manager
Published: Apr 20, 2026
Source: NVD
CVE-2026-32963 MEDIUM - 6.1

SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser.

Vendor: silex technology, Inc.
Product: SD-330AC, AMC Manager
Published: Apr 20, 2026
Source: NVD
CVE-2026-32962 MEDIUM - 5.3

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication.

Vendor: silex technology, Inc.
Product: SD-330AC, AMC Manager
Published: Apr 20, 2026
Source: NVD