Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
Showing 6,241 - 6,260 of 13,900 CVEs
CVE-2026-4666 MEDIUM - 6.5

The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions....

Published: Apr 17, 2026
Source: NVD
CVE-2026-5162 MEDIUM - 6.4

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it pos...

Published: Apr 17, 2026
Source: NVD
CVE-2026-4817 MEDIUM - 6.5

The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'order' and 'orderby' parameters in the /lms/stm-lms/order/items REST API endpoint in versions up to and including 3.7.25. This is du...

Published: Apr 17, 2026
Source: NVD
CVE-2026-3488 MEDIUM - 6.5

The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getPrivacyStatus`, `wp_statistics_updatePrivacyStatus`...

Published: Apr 17, 2026
Source: NVD
CVE-2026-40922 MEDIUM - 5.4

SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTML sanitizer, but the sanitizer does not block iframe tags, and its URL-prefix blocklist does not effe...

Vendor: siyuan-note
Product: siyuan
Published: Apr 17, 2026
Source: NVD
CVE-2026-40253 MEDIUM - 6.8

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (asn1.c) accept a raw pointer but no buffer length parameter, and trust attacker-controlled BER length fields without validating them ag...

Vendor: opencryptoki
Product: opencryptoki
Published: Apr 16, 2026
Source: NVD
CVE-2024-58343 MEDIUM - 4.3

Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.

Vendor: Vision
Product: Helpdesk
Published: Apr 16, 2026
Source: NVD
CVE-2026-34164 MEDIUM - 4.9

Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox messages can contain highly sensitive information including personal data (PII), citizen identifiers...

Vendor: valtimo-platform
Product: valtimo
Published: Apr 16, 2026
Source: NVD
CVE-2026-33472 MEDIUM - 4.8

Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The method hardcodes the URI scheme based on port number, causing...

Vendor: cryptomator
Product: cryptomator
Published: Apr 16, 2026
Source: NVD
CVE-2026-40602 MEDIUM - 5.6

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no r...

Vendor: pip
Product: homeassistant-cli
Published: Apr 16, 2026
Source: GitHub
CVE-2026-40304 MEDIUM - 5.3

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a frontend record has environment_id = NULL (the marker for admin-created global frontends), the condit...

Vendor: go
Product: github.com/openziti/zrok
Published: Apr 16, 2026
Source: GitHub
CVE-2026-40302 MEDIUM - 6.1

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/template. The GitHub OAuth callback handlers in both publicProxy and dynamicProxy embed the atta...

Vendor: go
Product: github.com/openziti/zrok
Published: Apr 16, 2026
Source: GitHub
CVE-2026-40899 MEDIUM - 6.5

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter for the illegalPar...

Vendor: dataease
Product: dataease
Published: Apr 16, 2026
Source: NVD
CVE-2025-43937 MEDIUM - 6.6

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to ...

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 16, 2026
Source: NVD
CVE-2025-43935 MEDIUM - 4.4

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 16, 2026
Source: NVD

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but ...

Vendor: ruby
Product: zlib
Published: Apr 16, 2026
Source: NVD
CVE-2026-24749 MEDIUM - 5.3

The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which by...

Vendor: silverstripe
Product: silverstripe-assets
Published: Apr 16, 2026
Source: NVD
CVE-2025-43883 MEDIUM - 4.1

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 16, 2026
Source: NVD
CVE-2025-36579 MEDIUM - 5.1

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37100 MEDIUM - 6.5

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol

Published: Apr 16, 2026
Source: NVD