Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,261 - 6,280 of 13,526 CVEs
CVE-2025-43937 MEDIUM - 6.6

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to ...

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 16, 2026
Source: NVD
CVE-2025-43935 MEDIUM - 4.4

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 16, 2026
Source: NVD

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but ...

Vendor: ruby
Product: zlib
Published: Apr 16, 2026
Source: NVD
CVE-2026-24749 MEDIUM - 5.3

The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which by...

Vendor: silverstripe
Product: silverstripe-assets
Published: Apr 16, 2026
Source: NVD
CVE-2025-43883 MEDIUM - 4.1

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 16, 2026
Source: NVD
CVE-2025-36579 MEDIUM - 5.1

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37100 MEDIUM - 6.5

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol

Published: Apr 16, 2026
Source: NVD
CVE-2026-37346 MEDIUM - 4.7

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.

Published: Apr 16, 2026
Source: NVD
CVE-2026-2840 MEDIUM - 6.4

The Email Encoder โ€“ Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for ...

Published: Apr 16, 2026
Source: NVD
CVE-2026-6410 MEDIUM - 5.3

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured static root using path.join() without a containment check. A remote unauthenticated attacker can obtain dir...

Vendor: npm
Product: @fastify/static
Published: Apr 16, 2026
Source: NVD
CVE-2026-4160 MEDIUM - 5.3

The Fluent Forms โ€“ Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownersh...

Published: Apr 16, 2026
Source: NVD
CVE-2026-31987 MEDIUM - 7.5

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 16, 2026
Source: NVD
CVE-2026-6414 MEDIUM - 5.9

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. This mismatch allows attackers to bypass route-based middleware or guards that protect files served by @fastify/stati...

Vendor: npm
Product: @fastify/static
Published: Apr 16, 2026
Source: NVD
CVE-2026-3369 MEDIUM - 5.4

The Better Find and Replace โ€“ AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

Published: Apr 16, 2026
Source: NVD
CVE-2025-12624 MEDIUM - 6.0

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequen...

Vendor: WSO2
Product: WSO2 Identity Server
Published: Apr 16, 2026
Source: NVD
CVE-2025-6024 MEDIUM - 6.1

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user's browser being redirected to a maliciou...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-4867 MEDIUM - 5.4

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-sit...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-10242 MEDIUM - 6.1

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim's browser. Successful exploitation can enable an ...

Vendor: WSO2
Product: WSO2 API Manager
Published: Apr 16, 2026
Source: NVD
CVE-2026-0718 MEDIUM - 5.3

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites โ€“ PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and including, 5.0.5. This makes it possible for unaut...

Published: Apr 16, 2026
Source: NVD
CVE-2026-41034 MEDIUM - 5.0

ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.

Vendor: Ascensio
Product: ONLYOFFICE DocumentServer
Published: Apr 16, 2026
Source: NVD