Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,361 - 6,380 of 13,538 CVEs
CVE-2026-20059 MEDIUM - 6.1

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-s...

Vendor: Cisco
Product: Cisco Unity Connection
Published: Apr 15, 2026
Source: NVD
CVE-2025-15636 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emarket-design YouTube Showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a through 3.5.1.

Vendor: Emarket-design
Product: YouTube Showcase
Published: Apr 15, 2026
Source: NVD
CVE-2025-15635 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through 1.6.0.

Vendor: Zaytech
Product: Smart Online Order for Clover
Published: Apr 15, 2026
Source: NVD
CVE-2026-20203 MEDIUM - 4.3

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission on...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Apr 15, 2026
Source: NVD
CVE-2026-20202 MEDIUM - 6.6

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a special...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Apr 15, 2026
Source: NVD
CVE-2025-53444 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a before 5.1.11.

Vendor: DeluxeThemes
Product: Userpro
Published: Apr 15, 2026
Source: NVD
CVE-2025-12141 MEDIUM - 6.5

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - c...

Vendor: Grafana
Product: Grafana Alerting
Published: Apr 15, 2026
Source: NVD
CVE-2026-4135 MEDIUM - 6.6

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

Published: Apr 15, 2026
Source: NVD
CVE-2026-25219 MEDIUM - 6.5

The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Azu...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 15, 2026
Source: NVD
CVE-2026-1636 MEDIUM - 6.7

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

Published: Apr 15, 2026
Source: NVD
CVE-2026-3590 MEDIUM - 6.5

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via ...

Vendor: mattermost
Product: mattermost_server
Published: Apr 15, 2026
Source: NVD
CVE-2026-1852 MEDIUM - 6.1

The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remove() functions. This makes it possible for unauthenticated attackers t...

Published: Apr 15, 2026
Source: NVD
CVE-2026-40786 MEDIUM - 4.3

Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.

Vendor: Long Watch Studio
Product: MyRewards
Published: Apr 15, 2026
Source: NVD
CVE-2026-40778 MEDIUM - 5.3

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2.

Vendor: Majestic Support
Product: Majestic Support
Published: Apr 15, 2026
Source: NVD
CVE-2026-40763 MEDIUM - 5.3

Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056.

Vendor: WP Royal
Product: Royal Elementor Addons
Published: Apr 15, 2026
Source: NVD
CVE-2026-40742 MEDIUM - 5.3

Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio AB Testing: from n/a through <= 8.2.8.

Vendor: Nelio Software
Product: Nelio AB Testing
Published: Apr 15, 2026
Source: NVD
CVE-2026-40740 MEDIUM - 5.4

Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7.

Vendor: Themeum
Product: Tutor LMS
Published: Apr 15, 2026
Source: NVD
CVE-2026-40737 MEDIUM - 5.3

Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects COMPE: from n/a through <= 1.1.4.

Vendor: VillaTheme
Product: COMPE
Published: Apr 15, 2026
Source: NVD
CVE-2026-40734 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories Images categories-images allows DOM-Based XSS.This issue affects Categories Images: from n/a through <= 3.3.1.

Vendor: Zahlan
Product: Categories Images
Published: Apr 15, 2026
Source: NVD
CVE-2026-40730 MEDIUM - 5.3

Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6.

Vendor: ThemeGrill
Product: ThemeGrill Demo Importer
Published: Apr 15, 2026
Source: NVD