Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
Showing 6,401 - 6,420 of 13,907 CVEs

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() ...

Vendor: go
Product: github.com/containers/podman/v4
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40883 MEDIUM - 8.1

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because gos...

Vendor: go
Product: github.com/patrickhener/goshs/v2
Published: Apr 14, 2026
Source: GitHub
CVE-2026-34370 MEDIUM - 6.5

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to read the private course notes of any other user on the platform by manipulating th...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 14, 2026
Source: NVD
CVE-2026-34213 MEDIUM - 5.4

Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization in Docmost allows a low-privileged authenticated user to overwrite another page's attachment within the same workspace by supplying a victim `attac...

Vendor: docmost
Product: docmost
Published: Apr 14, 2026
Source: NVD
CVE-2026-34212 MEDIUM - 5.4

Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralization of attachment URLs in Docmost allows a low-privileged authenticated user to store a malicious `javascript:` URL inside an attachment node in page content. When another user view...

Vendor: docmost
Product: docmost
Published: Apr 14, 2026
Source: NVD
CVE-2026-33193 MEDIUM - 4.6

Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of MIME type spoofing (GHSL-2026-052). An attacker could exploit this flaw to inject malicious scripts, potentially com...

Vendor: docmost
Product: docmost
Published: Apr 14, 2026
Source: NVD
CVE-2026-33146 MEDIUM - 4.3

Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets through the public search endpoint (`POST /api/search/share-search`) for publicly shared content. This ...

Vendor: docmost
Product: docmost
Published: Apr 14, 2026
Source: NVD
CVE-2025-15565 MEDIUM - 5.3

The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed.

Vendor: cartasi
Product: Nexi XPay
Published: Apr 14, 2026
Source: NVD

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler attributes (such as onclick or onload) could be bypassed using a c...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-25125 MEDIUM - 4.9

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attacke...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-27222 MEDIUM - 5.5

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a ...

Vendor: Adobe
Product: Bridge
Published: Apr 14, 2026
Source: NVD
CVE-2026-40255 MEDIUM - 6.1

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonisjs/core versions prior to 7.4.0, the response.redirect().back() method reads the Referer header from the incoming HTTP r...

Vendor: npm
Product: @adonisjs/http-server
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40249 MEDIUM - 5.3

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization erro...

Vendor: go
Product: github.com/free5gc/udr
Published: Apr 14, 2026
Source: GitHub
CVE-2026-34625 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-34624 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-34623 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-5754 MEDIUM - 6.1

Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.

Published: Apr 14, 2026
Source: NVD
CVE-2026-34614 MEDIUM - 6.1

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browse...

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-33829 MEDIUM - 4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-33822 MEDIUM - 6.1

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD