Total CVEs

139,258

Critical Severity

3,630

High Severity

13,017

Last 7 Days

1,247
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,561 - 6,580 of 12,714 CVEs
CVE-2026-5439 HIGH - 7.5

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causi...

Vendor: orthanc-server
Product: orthanc
Published: Apr 09, 2026
Source: NVD
CVE-2026-5438 HIGH - 7.5

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on attacker-controlled compression metadata. A specially crafted gzip payload can trigger excessive mem...

Vendor: orthanc-server
Product: orthanc
Published: Apr 09, 2026
Source: NVD
CVE-2026-5437 HIGH - 7.5

An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocated metadata buffer. Although this issue does not typically crash the server or expose data directly t...

Vendor: orthanc-server
Product: orthanc
Published: Apr 09, 2026
Source: NVD
CVE-2026-4116 HIGH - 7.2

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

Published: Apr 09, 2026
Source: NVD
CVE-2026-4113 HIGH - 7.2

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.

Published: Apr 09, 2026
Source: NVD
CVE-2026-34578 HIGH - 8.2

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters into the username f...

Vendor: opnsense
Product: core
Published: Apr 09, 2026
Source: NVD
CVE-2025-70810 HIGH - 8.8

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism

Published: Apr 09, 2026
Source: NVD
CVE-2026-4660 HIGH - 7.5

HashiCorpโ€™s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

Vendor: go
Product: github.com/hashicorp/go-getter
Published: Apr 09, 2026
Source: NVD
CVE-2024-1490 HIGH - 7.2

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the ...

Published: Apr 09, 2026
Source: NVD
CVE-2025-62188 HIGH - 7.5

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are r...

Vendor: Apache Software Foundation
Product: Apache DolphinScheduler
Published: Apr 09, 2026
Source: NVD
CVE-2026-5849 HIGH - 7.3

A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Published: Apr 09, 2026
Source: NVD
CVE-2026-5844 HIGH - 7.2

A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5842 HIGH - 7.3

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has be...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5841 HIGH - 7.3

A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5837 HIGH - 7.3

A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

Published: Apr 09, 2026
Source: NVD
CVE-2026-5832 HIGH - 7.3

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5830 HIGH - 8.8

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5829 HIGH - 7.3

A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly dis...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5828 HIGH - 7.3

A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and co...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4326 HIGH - 8.8

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capabi...

Published: Apr 09, 2026
Source: NVD