Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,361 - 6,380 of 12,679 CVEs
CVE-2026-6121 HIGH - 8.8

A flaw has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function WrlclientSet of the file /goform/WrlclientSet of the component httpd. This manipulation of the argument GO causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publis...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6120 HIGH - 8.8

A vulnerability was detected in Tenda F451 1.0.0.7. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and ...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6110 HIGH - 7.3

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is pu...

Vendor: pip
Product: metagpt
Published: Apr 12, 2026
Source: NVD
CVE-2026-1116 HIGH - 8.2

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This al...

Vendor: lollms
Product: lollms
Published: Apr 12, 2026
Source: NVD
CVE-2026-6105 HIGH - 7.3

A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.java of the component doInstall Interface. The manipulation leads to improper authorization. The attack may be initiated r...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5809 HIGH - 7.1

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5217 HIGH - 7.2

The Optimole โ€“ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due to insufficient input sanitization and output escaping on the user-supplied &...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5144 HIGH - 8.8

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-silent-add` parameters from user input without proper aut...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5496 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in that th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5495 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5494 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5493 HIGH - 7.8

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in th...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5055 HIGH - 7.8

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exp...

Vendor: nomachine
Product: nomachine
Published: Apr 11, 2026
Source: NVD
CVE-2026-5054 HIGH - 7.8

NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit...

Vendor: nomachine
Product: nomachine
Published: Apr 11, 2026
Source: NVD
CVE-2026-5053 HIGH - 7.1

NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers to delete arbitrary files on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit...

Vendor: nomachine
Product: nomachine
Published: Apr 11, 2026
Source: NVD
CVE-2026-4158 HIGH - 7.3

KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged code on the target s...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4157 HIGH - 7.5

ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex devices. Authentication is not required to exploit this vulnerability. The sp...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4156 HIGH - 7.5

ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex EV chargers. Authentication is not required to exploit this vulnerabil...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4155 HIGH - 7.5

ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit t...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4154 HIGH - 7.8

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mali...

Vendor: gimp
Product: gimp
Published: Apr 11, 2026
Source: NVD