Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

935
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 6,481 - 6,500 of 12,679 CVEs
CVE-2026-33778 HIGH - 7.5

An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). If an affected device receives a ...

Vendor: Juniper Networks
Product: Junos OS
Published: Apr 09, 2026
Source: NVD
CVE-2026-33771 HIGH - 7.4

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the admi...

Vendor: Juniper Networks
Product: CTP OS
Published: Apr 09, 2026
Source: NVD
CVE-2026-21916 HIGH - 7.3

A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root which will lead to a complete compromise of the system. When after a user has performed a specific 'fil...

Vendor: Juniper Networks
Product: Junos OS
Published: Apr 09, 2026
Source: NVD
CVE-2025-13914 HIGH - 8.7

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH con...

Vendor: Juniper Networks
Product: Apstra
Published: Apr 09, 2026
Source: NVD
CVE-2026-5980 HIGH - 8.8

A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit ha...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5979 HIGH - 8.8

A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely....

Published: Apr 09, 2026
Source: NVD
CVE-2026-40107 HIGH - 6.5

SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with src attributes survive Mermaid's internal DOMPurify and land in SVG <foreignObject> blocks. The SV...

Vendor: siyuan-note
Product: siyuan
Published: Apr 09, 2026
Source: NVD
CVE-2026-40093 HIGH - 8.1

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for non-skip blocks and timestamp == parent.timestamp + MIN_PRODUCER_TIMEOUT for skip blocks, but there is no visib...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 09, 2026
Source: NVD
CVE-2023-54359 HIGH - 8.2

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted &...

Vendor: Adivaha
Product: WordPress adivaha Travel Plugin
Published: Apr 09, 2026
Source: NVD
CVE-2026-5974 HIGH - 7.3

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the probl...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5973 HIGH - 7.3

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was in...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5972 HIGH - 7.3

A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4436 HIGH - 8.6

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

Published: Apr 09, 2026
Source: NVD
CVE-2026-35063 HIGH - 8.8

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator acc...

Vendor: OpenPLC_V3
Product: OpenPLC_V3
Published: Apr 09, 2026
Source: NVD
CVE-2026-34734 HIGH - 7.8

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was...

Vendor: HDFGroup
Product: hdf5
Published: Apr 09, 2026
Source: NVD
CVE-2026-34487 HIGH - 7.5

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-34486 HIGH - 7.5

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to theΒ fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the i...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-34483 HIGH - 7.5

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-29923 HIGH - 7.8

The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged users to map arbitrary physical memory into their address space and modify critical kernel structures.

Published: Apr 09, 2026
Source: NVD
CVE-2026-29146 HIGH - 7.5

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are rec...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD