Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,301 - 6,320 of 13,526 CVEs
CVE-2026-3885 MEDIUM - 6.4

The WP Shortcodes Plugin โ€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Published: Apr 16, 2026
Source: NVD
CVE-2026-40962 MEDIUM - 4.9

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

Vendor: FFMpeg
Product: FFMpeg
Published: Apr 16, 2026
Source: NVD
CVE-2026-3299 MEDIUM - 6.4

The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode in all versions up to, and including, 1.7.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...

Published: Apr 16, 2026
Source: NVD
CVE-2026-40353 MEDIUM - 5.4

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) without escaping, and templates render the result using Django&#...

Vendor: pip
Product: wger
Published: Apr 16, 2026
Source: GitHub
CVE-2026-40594 MEDIUM - 4.8

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without validating that the request originates from a trusted...

Vendor: pip
Product: pyload-ng
Published: Apr 16, 2026
Source: GitHub
CVE-2026-40503 MEDIUM - 6.5

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /memory show slash command. Attackers can manipulate the path input parameter to escape the project memor...

Vendor: HKUDS
Product: OpenHarness
Published: Apr 16, 2026
Source: NVD
CVE-2026-4949 MEDIUM - 4.3

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content โ€“ ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is due to the 'process_checkout' function not proper...

Published: Apr 15, 2026
Source: NVD
CVE-2026-39350 MEDIUM - 5.4

Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1, the serviceAccounts and notServiceAccounts fields in AuthorizationPolicy incorrectly interpret dots (.) as a regular expression matcher. Because . is ...

Vendor: istio
Product: istio
Published: Apr 15, 2026
Source: NVD
CVE-2026-40500 MEDIUM - 6.8

ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arbitrary URLs to the module download parameter, causing the server to issue outbound HTT...

Vendor: processwire
Product: processwire
Published: Apr 15, 2026
Source: NVD
CVE-2026-40186 MEDIUM - 6.1

ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags enforcement for text inside nonTextTagsArray elements (textarea and option). Apostrophe...

Vendor: apostrophecms
Product: apostrophe, sanitize-html
Published: Apr 15, 2026
Source: NVD
CVE-2026-6385 MEDIUM - 6.5

A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds ch...

Published: Apr 15, 2026
Source: NVD
CVE-2026-6364 MEDIUM - 6.5

Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: Apr 15, 2026
Source: NVD
CVE-2026-6362 MEDIUM - 6.3

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 15, 2026
Source: NVD
CVE-2026-6298 MEDIUM - 4.3

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: Apr 15, 2026
Source: NVD
CVE-2026-40919 MEDIUM - 6.1

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potentia...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Apr 15, 2026
Source: NVD
CVE-2026-40918 MEDIUM - 5.5

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted PV...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Apr 15, 2026
Source: NVD
CVE-2026-40917 MEDIUM - 5.0

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that proce...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Apr 15, 2026
Source: NVD
CVE-2026-40916 MEDIUM - 5.0

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Apr 15, 2026
Source: NVD
CVE-2026-40915 MEDIUM - 5.5

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data....

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Apr 15, 2026
Source: NVD
CVE-2026-39857 MEDIUM - 5.3

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute MongoDB distinct() operations that bypass the publicApiProjection ...

Vendor: apostrophecms
Product: apostrophe
Published: Apr 15, 2026
Source: NVD