Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,201 - 6,220 of 13,526 CVEs
CVE-2026-40155 MEDIUM - 5.4

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. Users are affected if thei...

Vendor: auth0
Product: nextjs-auth0
Published: Apr 17, 2026
Source: NVD
CVE-2026-35603 MEDIUM - 7.3

Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions. Because the ProgramData directory is writable by ...

Vendor: anthropics
Product: claude-code
Published: Apr 17, 2026
Source: NVD
CVE-2026-33145 MEDIUM - 6.3

xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When the AllowAlternateShell setting is enabled (which is the default when not explicitly c...

Vendor: neutrinolabs
Product: xrdp
Published: Apr 17, 2026
Source: NVD
CVE-2026-40283 MEDIUM - 6.8

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the "Nome" field in the "Informações Pacientes" page. The payload is stored and execu...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 17, 2026
Source: NVD
CVE-2026-35061 MEDIUM - 5.3

Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operational imagery.

Vendor: Anviz
Product: Anviz CX7 Firmware
Published: Apr 17, 2026
Source: NVD
CVE-2026-33569 MEDIUM - 6.5

Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device.

Vendor: Anviz
Product: Anviz CX7 Firmware, Anviz CX2 Lite Firmware
Published: Apr 17, 2026
Source: NVD
CVE-2026-33093 MEDIUM - 5.3

Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing camera, exposing visual information about the deployment environment.

Vendor: Anviz
Product: Anviz CX7 Firmware
Published: Apr 17, 2026
Source: NVD
CVE-2026-32648 MEDIUM - 5.3

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attackers in reconnaissance against the device.

Vendor: Anviz
Product: Anviz CX7 Firmware, Anviz CX2 Lite Firmware
Published: Apr 17, 2026
Source: NVD
CVE-2026-31927 MEDIUM - 4.9

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes

Vendor: Anviz
Product: Anviz CX7 Firmware
Published: Apr 17, 2026
Source: NVD
CVE-2026-6437 MEDIUM - 6.5

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, us...

Vendor: go
Product: github.com/kubernetes-sigs/aws-efs-csi-driver
Published: Apr 17, 2026
Source: NVD
CVE-2026-28214 MEDIUM - 6.5

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, causing an infinite loop. An authenticated user with INSERT privileges ...

Vendor: FirebirdSQL
Product: firebird
Published: Apr 17, 2026
Source: NVD
CVE-2026-6497 MEDIUM - 6.3

A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulation of the argument uploadurl causes server-side request f...

Published: Apr 17, 2026
Source: NVD
CVE-2026-21709 MEDIUM - 6.7

A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.

Vendor: Veeam
Product: Backup and Replication, Software Appliance
Published: Apr 17, 2026
Source: NVD
CVE-2026-6496 MEDIUM - 5.4

A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. The attack may be performed from remote. The exploit has been m...

Published: Apr 17, 2026
Source: NVD
CVE-2026-41153 MEDIUM - 5.8

In JetBrains Junie before 252.549.29 command execution was possible via malicious project file

Vendor: JetBrains
Product: Junie
Published: Apr 17, 2026
Source: NVD
CVE-2026-6492 MEDIUM - 5.3

A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in information disclosure. R...

Published: Apr 17, 2026
Source: NVD
CVE-2026-6491 MEDIUM - 5.3

A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based buffer overflow. An attack has to be approached l...

Published: Apr 17, 2026
Source: NVD
CVE-2026-31317 MEDIUM - 7.5

Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file

Vendor: composer
Product: markhuot/craftql
Published: Apr 17, 2026
Source: NVD
CVE-2025-70795 MEDIUM - 5.5

STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enab...

Published: Apr 17, 2026
Source: NVD
CVE-2026-6489 MEDIUM - 6.3

A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation of the argument image results in unrestricted upload. The att...

Published: Apr 17, 2026
Source: NVD