Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,421 - 6,440 of 13,538 CVEs

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler attributes (such as onclick or onload) could be bypassed using a c...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-25125 MEDIUM - 4.9

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attacke...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-27222 MEDIUM - 5.5

Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a ...

Vendor: Adobe
Product: Bridge
Published: Apr 14, 2026
Source: NVD
CVE-2026-40255 MEDIUM - 6.1

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonisjs/core versions prior to 7.4.0, the response.redirect().back() method reads the Referer header from the incoming HTTP r...

Vendor: npm
Product: @adonisjs/http-server
Published: Apr 14, 2026
Source: GitHub
CVE-2026-40249 MEDIUM - 5.3

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization erro...

Vendor: go
Product: github.com/free5gc/udr
Published: Apr 14, 2026
Source: GitHub
CVE-2026-34625 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-34624 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-34623 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-5754 MEDIUM - 6.1

Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.

Published: Apr 14, 2026
Source: NVD
CVE-2026-34614 MEDIUM - 6.1

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browse...

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-33829 MEDIUM - 4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-33822 MEDIUM - 6.1

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-33103 MEDIUM - 5.5

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-32226 MEDIUM - 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-32223 MEDIUM - 6.8

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Vendor: microsoft
Product: windows_11_24h2
Published: Apr 14, 2026
Source: NVD
CVE-2026-32220 MEDIUM - 4.4

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Vendor: microsoft
Product: windows_11_24h2
Published: Apr 14, 2026
Source: NVD
CVE-2026-32218 MEDIUM - 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_21h2
Published: Apr 14, 2026
Source: NVD
CVE-2026-32217 MEDIUM - 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32216 MEDIUM - 5.5

Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.

Vendor: microsoft
Product: windows_11_26h1
Published: Apr 14, 2026
Source: NVD
CVE-2026-32215 MEDIUM - 5.5

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1809
Published: Apr 14, 2026
Source: NVD