Total CVEs

139,258

Critical Severity

3,630

High Severity

13,017

Last 7 Days

1,248
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 6,521 - 6,540 of 12,714 CVEs
CVE-2026-5979 HIGH - 8.8

A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely....

Published: Apr 09, 2026
Source: NVD
CVE-2026-40107 HIGH - 6.5

SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with src attributes survive Mermaid's internal DOMPurify and land in SVG <foreignObject> blocks. The SV...

Vendor: siyuan-note
Product: siyuan
Published: Apr 09, 2026
Source: NVD
CVE-2026-40093 HIGH - 8.1

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for non-skip blocks and timestamp == parent.timestamp + MIN_PRODUCER_TIMEOUT for skip blocks, but there is no visib...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 09, 2026
Source: NVD
CVE-2023-54359 HIGH - 8.2

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted &...

Vendor: Adivaha
Product: WordPress adivaha Travel Plugin
Published: Apr 09, 2026
Source: NVD
CVE-2026-5974 HIGH - 7.3

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the probl...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5973 HIGH - 7.3

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was in...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5972 HIGH - 7.3

A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4436 HIGH - 8.6

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

Published: Apr 09, 2026
Source: NVD
CVE-2026-35063 HIGH - 8.8

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator acc...

Vendor: OpenPLC_V3
Product: OpenPLC_V3
Published: Apr 09, 2026
Source: NVD
CVE-2026-34734 HIGH - 7.8

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was...

Vendor: HDFGroup
Product: hdf5
Published: Apr 09, 2026
Source: NVD
CVE-2026-34487 HIGH - 7.5

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-34486 HIGH - 7.5

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to theΒ fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the i...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-34483 HIGH - 7.5

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-29923 HIGH - 7.8

The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged users to map arbitrary physical memory into their address space and modify critical kernel structures.

Published: Apr 09, 2026
Source: NVD
CVE-2026-29146 HIGH - 7.5

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are rec...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-29129 HIGH - 7.5

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-24880 HIGH - 7.5

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through ...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Apr 09, 2026
Source: NVD
CVE-2026-35556 HIGH - 7.5

OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.

Vendor: OpenPLC_V3
Product: OpenPLC_V3
Published: Apr 09, 2026
Source: NVD
CVE-2026-5971 HIGH - 7.3

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5970 HIGH - 7.3

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The ...

Published: Apr 09, 2026
Source: NVD