Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,561 - 6,580 of 13,553 CVEs
CVE-2026-34238 MEDIUM - 5.1

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, an integer overflow in the despeckle operation causes a heap buffer overflow on 32-bit builds that will result in an out of bounds write. This issue has been ...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-33947 MEDIUM - 6.2

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can suppl...

Vendor: jqlang
Product: jq
Published: Apr 13, 2026
Source: NVD
CVE-2026-33905 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. Th...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-33902 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression. Thi...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-6219 MEDIUM - 5.3

A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly d...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6218 MEDIUM - 4.3

A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosu...

Published: Apr 13, 2026
Source: NVD
CVE-2026-33900 MEDIUM - 5.9

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash....

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-33899 MEDIUM - 5.3

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19...

Vendor: ImageMagick
Product: ImageMagick
Published: Apr 13, 2026
Source: NVD
CVE-2026-33740 MEDIUM - 5.4

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parameter is used to fetch any attachment directly from ...

Vendor: espocrm
Product: espocrm
Published: Apr 13, 2026
Source: NVD
CVE-2026-26460 MEDIUM - 6.1

A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into the dashboard interf...

Published: Apr 13, 2026
Source: NVD
CVE-2025-70936 MEDIUM - 5.4

Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and executed in the context of an authenticated user s ...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6215 MEDIUM - 6.3

A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6202 MEDIUM - 6.3

A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used f...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6201 MEDIUM - 5.4

A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. Th...

Published: Apr 13, 2026
Source: NVD
CVE-2026-33657 MEDIUM - 4.6

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into system-generated email notifications by crafting ...

Vendor: espocrm
Product: espocrm
Published: Apr 13, 2026
Source: NVD
CVE-2026-33534 MEDIUM - 4.3

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows bypassing the internal-host validation logic by using alternative IPv4 representations such as octal notation (e.g., 017...

Vendor: espocrm
Product: espocrm
Published: Apr 13, 2026
Source: NVD
CVE-2026-40265 MEDIUM - 5.9

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware, and the backend query does not verify ownership or book visibility. An unauthenticated user who know...

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 13, 2026
Source: GitHub
CVE-2026-40043 MEDIUM - 6.5

Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate privileges by manipulating the original_username cookie. Attackers can set the client-controlled original_username cookie to any value and request a sw...

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD
CVE-2026-40041 MEDIUM - 4.3

Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protections on state-changing endpoints. Attackers can craft malicious requests targeting login, registration, file upload, mil...

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD
CVE-2026-40039 MEDIUM - 6.5

Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to conduct phishing attacks and steal user credentials.

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD