Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
Showing 6,261 - 6,280 of 13,903 CVEs
CVE-2025-43883 MEDIUM - 4.1

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 16, 2026
Source: NVD
CVE-2025-36579 MEDIUM - 5.1

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37100 MEDIUM - 6.5

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio range to connect without authentication via the Sound Bar Remote protocol

Published: Apr 16, 2026
Source: NVD
CVE-2026-37346 MEDIUM - 4.7

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.

Published: Apr 16, 2026
Source: NVD
CVE-2026-2840 MEDIUM - 6.4

The Email Encoder โ€“ Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for ...

Published: Apr 16, 2026
Source: NVD
CVE-2026-6410 MEDIUM - 5.3

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured static root using path.join() without a containment check. A remote unauthenticated attacker can obtain dir...

Vendor: npm
Product: @fastify/static
Published: Apr 16, 2026
Source: NVD
CVE-2026-4160 MEDIUM - 5.3

The Fluent Forms โ€“ Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownersh...

Published: Apr 16, 2026
Source: NVD
CVE-2026-31987 MEDIUM - 7.5

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 16, 2026
Source: NVD
CVE-2026-6414 MEDIUM - 5.9

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. This mismatch allows attackers to bypass route-based middleware or guards that protect files served by @fastify/stati...

Vendor: npm
Product: @fastify/static
Published: Apr 16, 2026
Source: NVD
CVE-2026-3369 MEDIUM - 5.4

The Better Find and Replace โ€“ AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

Published: Apr 16, 2026
Source: NVD
CVE-2025-12624 MEDIUM - 6.0

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequen...

Vendor: WSO2
Product: WSO2 Identity Server
Published: Apr 16, 2026
Source: NVD
CVE-2025-6024 MEDIUM - 6.1

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user's browser being redirected to a maliciou...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-4867 MEDIUM - 5.4

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-sit...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-10242 MEDIUM - 6.1

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim's browser. Successful exploitation can enable an ...

Vendor: WSO2
Product: WSO2 API Manager
Published: Apr 16, 2026
Source: NVD
CVE-2026-0718 MEDIUM - 5.3

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites โ€“ PostX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ultp_shareCount_callback() function in all versions up to, and including, 5.0.5. This makes it possible for unaut...

Published: Apr 16, 2026
Source: NVD
CVE-2026-41034 MEDIUM - 5.0

ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.

Vendor: Ascensio
Product: ONLYOFFICE DocumentServer
Published: Apr 16, 2026
Source: NVD
CVE-2026-41030 MEDIUM - 6.2

In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.

Vendor: Ascensio
Product: ONLYOFFICE DesktopEditors
Published: Apr 16, 2026
Source: NVD
CVE-2026-3995 MEDIUM - 4.4

The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all versions up to, and including, 0.5.0. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() which strips HTML tags bu...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3875 MEDIUM - 6.4

The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3861 MEDIUM - 6.5

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs, potentially causing the iOS device to become temporarily inoperable.

Published: Apr 16, 2026
Source: NVD