Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,788
Quick preset (or use dates below)
Clear Filters
Showing 6,501 - 6,520 of 13,919 CVEs
CVE-2026-37980 MEDIUM - 6.9

A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed in...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: Apr 14, 2026
Source: NVD
CVE-2026-30480 MEDIUM - 6.5

A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.

Published: Apr 14, 2026
Source: NVD
CVE-2025-69993 MEDIUM - 6.1

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x o...

Vendor: leafletjs
Product: leaflet
Published: Apr 14, 2026
Source: NVD
CVE-2025-69893 MEDIUM - 4.6

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant time...

Published: Apr 14, 2026
Source: NVD
CVE-2026-24069 MEDIUM - 5.4

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

Vendor: Kiuwan
Product: SAST
Published: Apr 14, 2026
Source: NVD
CVE-2026-4109 MEDIUM - 4.3

The Eventin โ€“ Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible f...

Published: Apr 14, 2026
Source: NVD
CVE-2026-33929 MEDIUM - 4.3

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are recommended to update to version...

Vendor: Apache Software Foundation
Product: Apache PDFBox Examples
Published: Apr 14, 2026
Source: NVD
CVE-2026-31924 MEDIUM - 5.3

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache APISIX
Published: Apr 14, 2026
Source: NVD
CVE-2026-2582 MEDIUM - 6.5

The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before...

Published: Apr 14, 2026
Source: NVD
CVE-2026-4479 MEDIUM - 4.4

The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Published: Apr 14, 2026
Source: NVD
CVE-2026-4059 MEDIUM - 6.4

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcod...

Published: Apr 14, 2026
Source: NVD
CVE-2026-1607 MEDIUM - 6.4

The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...

Published: Apr 14, 2026
Source: NVD
CVE-2026-39426 MEDIUM - 5.4

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom <iframe_render> tags from LLM responses or Application Prologue configurations, bypassing sta...

Vendor: 1Panel-dev
Product: MaxKB
Published: Apr 14, 2026
Source: NVD
CVE-2026-39425 MEDIUM - 5.4

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability that allows authenticated users to inject arbitrary HTML and JavaScript into the Application prologue (Opening Remarks) field by wrapping malicious payloads in <...

Vendor: 1Panel-dev
Product: MaxKB
Published: Apr 14, 2026
Source: NVD
CVE-2026-34225 MEDIUM - 4.3

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forgery in the functionality that allows editing an image via a prompt. The affected function performs a GET request to a user-provided URL ...

Vendor: open-webui
Product: open-webui
Published: Apr 14, 2026
Source: NVD
CVE-2026-39424 MEDIUM - 4.7

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable to Improper Neutralization of Formula Elements in a CSV File. When an administrator exports the application chat history to an Excel file (.xlsx) via the /admin/api/workspace/{work...

Vendor: 1Panel-dev
Product: MaxKB
Published: Apr 14, 2026
Source: NVD
CVE-2026-39423 MEDIUM - 5.4

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting with the AI chat interface to execute arbitrary JavaScript in the browsers of other users, including admi...

Vendor: 1Panel-dev
Product: MaxKB
Published: Apr 14, 2026
Source: NVD
CVE-2026-39422 MEDIUM - 5.4

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability through the application name or icon fields when creating an application. When a victim visits the public chat interface (/ui/chat/{access_token}), the ChatHeadersM...

Vendor: 1Panel-dev
Product: MaxKB
Published: Apr 14, 2026
Source: NVD
CVE-2026-39421 MEDIUM - 6.3

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. By leveraging Python's ctypes library to execute raw system calls, an authenticated attacker with workspace privileges can bypass the LD_PRELOAD-ba...

Vendor: 1Panel-dev
Product: MaxKB
Published: Apr 14, 2026
Source: NVD
CVE-2026-39420 MEDIUM - 6.3

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mechanism allows an authenticated user with tool execution privileges to escape the LD_PRELOAD-based sandbox. By env command the attacker can clear the environment variables and drop th...

Vendor: 1Panel-dev
Product: MaxKB
Published: Apr 14, 2026
Source: NVD