Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
Showing 6,561 - 6,580 of 13,919 CVEs
CVE-2026-33534 MEDIUM - 4.3

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows bypassing the internal-host validation logic by using alternative IPv4 representations such as octal notation (e.g., 017...

Vendor: espocrm
Product: espocrm
Published: Apr 13, 2026
Source: NVD
CVE-2026-40265 MEDIUM - 5.9

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware, and the backend query does not verify ownership or book visibility. An unauthenticated user who know...

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 13, 2026
Source: GitHub
CVE-2026-40043 MEDIUM - 6.5

Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate privileges by manipulating the original_username cookie. Attackers can set the client-controlled original_username cookie to any value and request a sw...

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD
CVE-2026-40041 MEDIUM - 4.3

Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protections on state-changing endpoints. Attackers can craft malicious requests targeting login, registration, file upload, mil...

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD
CVE-2026-40039 MEDIUM - 6.5

Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to conduct phishing attacks and steal user credentials.

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD
CVE-2025-3756 MEDIUM - 6.5

A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing the communication in...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6191 MEDIUM - 6.3

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and m...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6190 MEDIUM - 6.3

A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /employees.php. Performing a manipulation of the argument Name results in sql injection. The attack can be initiated remotely. The exploit has been made public and co...

Published: Apr 13, 2026
Source: NVD
CVE-2026-33555 MEDIUM - 4.0

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used...

Vendor: HAProxy
Product: HAProxy
Published: Apr 13, 2026
Source: NVD
CVE-2026-40179 MEDIUM - 6.1

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escapi...

Vendor: go
Product: github.com/prometheus/prometheus
Published: Apr 13, 2026
Source: GitHub
CVE-2026-34069 MEDIUM - 5.3

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 and below, an unauthenticated p2p peer can cause the RequestMacroChain message handler task to panic. Sending a RequestMacroChain message where the firs...

Vendor: rust
Product: nimiq-consensus
Published: Apr 13, 2026
Source: GitHub
CVE-2026-6231 MEDIUM - 4.3

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely...

Published: Apr 13, 2026
Source: NVD
CVE-2025-63743 MEDIUM - 5.4

Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 allows authenticated attacker with lowest privileges sufficient only to log in, to inject arbitrary JavaScript code via "Name" and "Surname" fields. The JavaScri...

Published: Apr 13, 2026
Source: NVD
CVE-2025-31991 MEDIUM - 6.8

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.ย  This vulnerability is fixed in 5.1.7.

Vendor: HCLSoftware
Product: Velocity
Published: Apr 13, 2026
Source: NVD
CVE-2026-29628 MEDIUM - 6.2

A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file.

Published: Apr 13, 2026
Source: NVD
CVE-2026-2728 MEDIUM - 3.5

LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.

Vendor: composer
Product: librenms/librenms
Published: Apr 13, 2026
Source: NVD
CVE-2026-35565 MEDIUM - 5.4

Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in p...

Vendor: Apache Software Foundation
Product: Apache Storm UI
Published: Apr 13, 2026
Source: NVD
CVE-2026-34866 MEDIUM - 5.1

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Vendor: Huawei
Product: HarmonyOS
Published: Apr 13, 2026
Source: NVD
CVE-2025-15441 MEDIUM - 6.8

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

Vendor: Unknown
Product: Form Maker by 10Web
Published: Apr 13, 2026
Source: NVD
CVE-2026-40447 MEDIUM - 5.1

Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.

Vendor: Samsung Open Source
Product: Escargot
Published: Apr 13, 2026
Source: NVD