Total CVEs

139,258

Critical Severity

3,630

High Severity

13,017

Last 7 Days

1,247
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,541 - 6,560 of 12,714 CVEs
CVE-2026-5329 HIGH - 8.5

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring me...

Published: Apr 09, 2026
Source: NVD
CVE-2026-40070 HIGH - 8.1

BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier's signature over the certificate contents. In acquisition_protocol: 'direct', the call...

Vendor: sgbett
Product: bsv-ruby-sdk, bsv-sdk, bsv-wallet
Published: Apr 09, 2026
Source: NVD
CVE-2026-40069 HIGH - 7.5

BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStat...

Vendor: sgbett
Product: bsv-ruby-sdk
Published: Apr 09, 2026
Source: NVD
CVE-2026-39911 HIGH - 8.8

Hashgraph Guardian through version 3.5.0 contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows authenticated Standard Registry users to execute arbitrary code by passing user-supplied JavaScript expressions directly to the Node.js Function() c...

Vendor: hashgraph
Product: guardian
Published: Apr 09, 2026
Source: NVD
CVE-2026-30478 HIGH - 8.8

A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable.

Published: Apr 09, 2026
Source: NVD
CVE-2026-1584 HIGH - 7.5

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and re...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5962 HIGH - 7.3

A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.

Published: Apr 09, 2026
Source: NVD
CVE-2026-5961 HIGH - 7.3

A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects unknown code of the file /topic-details.php. The manipulation of the argument post_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed pu...

Published: Apr 09, 2026
Source: NVD
CVE-2026-39976 HIGH - 7.1

Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this v...

Vendor: laravel
Product: passport
Published: Apr 09, 2026
Source: NVD
CVE-2026-39942 HIGH - 8.5

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's...

Vendor: directus
Product: directus
Published: Apr 09, 2026
Source: NVD
CVE-2026-39853 HIGH - 7.8

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7 signature, the code copies the digest value from a parsed SpcIndirectData...

Vendor: mtrojnar
Product: osslsigncode
Published: Apr 09, 2026
Source: NVD
CVE-2026-39843 HIGH - 7.7

Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server-Side Request Forgery when a normal html page contains a link tag with an href that redirects to a private IP address is ...

Vendor: makeplane
Product: plane
Published: Apr 09, 2026
Source: NVD

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

Vendor: helm
Product: helm
Published: Apr 09, 2026
Source: NVD

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not in...

Vendor: helm
Product: helm
Published: Apr 09, 2026
Source: NVD
CVE-2026-34020 HIGH - 7.5

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 bef...

Vendor: Apache Software Foundation
Product: Apache OpenMeetings
Published: Apr 09, 2026
Source: NVD
CVE-2026-33266 HIGH - 7.5

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a ...

Vendor: Apache Software Foundation
Product: Apache OpenMeetings
Published: Apr 09, 2026
Source: NVD
CVE-2025-70364 HIGH - 8.8

An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server.

Published: Apr 09, 2026
Source: NVD
CVE-2026-5444 HIGH - 7.1

A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, image dimensions are multiplied using 32-bit unsigned arithmetic. Specially chosen values can cause an integer overflow during buffer size calculation, res...

Vendor: orthanc-server
Product: orthanc
Published: Apr 09, 2026
Source: NVD
CVE-2026-5441 HIGH - 7.1

An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A cr...

Vendor: orthanc-server
Product: orthanc
Published: Apr 09, 2026
Source: NVD
CVE-2026-5440 HIGH - 7.5

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A crafted HTTP request containing an extremely large `Content-Length` v...

Vendor: orthanc-server
Product: orthanc
Published: Apr 09, 2026
Source: NVD