Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,621 - 6,640 of 13,553 CVEs
CVE-2026-28553 MEDIUM - 6.9

Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Vendor: Huawei
Product: HarmonyOS, EMUI
Published: Apr 13, 2026
Source: NVD
CVE-2026-6150 MEDIUM - 4.3

A vulnerability has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /checkupdatestatus.php. The manipulation of the argument serviceId leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the ...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6143 MEDIUM - 6.3

A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive cross-domain policy with untrusted domains. The attack can be ...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6141 MEDIUM - 6.3

A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/Tools/parse_url.ts. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclos...

Published: Apr 13, 2026
Source: NVD
CVE-2026-25204 MEDIUM - 6.2

Deserialization of untrusted data vulnerability in Samsung Open Source Escarogt Java Script allows denial of service condition via process abort. This issue affects escarogt prior toย commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335

Vendor: Samsung Open Source
Product: Escargot
Published: Apr 13, 2026
Source: NVD
CVE-2026-40396 MEDIUM - 4.0

Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linger) and resume traffic before the session is closed ...

Vendor: varnish-software
Product: Varnish Cache
Published: Apr 12, 2026
Source: NVD
CVE-2026-40395 MEDIUM - 4.0

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and...

Vendor: varnish-software
Product: Varnish Enterprise
Published: Apr 12, 2026
Source: NVD
CVE-2026-40394 MEDIUM - 4.0

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request...

Vendor: varnish-software
Product: Varnish Cache
Published: Apr 12, 2026
Source: NVD
CVE-2026-40386 MEDIUM - 4.0

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

Vendor: libexif project
Product: libexif
Published: Apr 12, 2026
Source: NVD
CVE-2026-40385 MEDIUM - 4.0

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

Vendor: libexif project
Product: libexif
Published: Apr 12, 2026
Source: NVD
CVE-2019-25712 MEDIUM - 6.2

BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration...

Vendor: NSauditor
Product: BlueAuditor
Published: Apr 12, 2026
Source: NVD
CVE-2019-25711 MEDIUM - 6.2

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash wh...

Vendor: NSauditor
Product: SpotFTP Password Recover
Published: Apr 12, 2026
Source: NVD
CVE-2019-25708 MEDIUM - 4.3

Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm,...

Vendor: Heatmiser
Product: Heatmiser Wifi Thermostat
Published: Apr 12, 2026
Source: NVD
CVE-2017-20239 MEDIUM - 6.1

MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by injecting malicious code through the location hash parameter. Attackers can craft URLs with JavaScript payloads in the hash fragment that are parsed and rendered without sanitization,...

Vendor: Dynalon
Product: MDwiki
Published: Apr 12, 2026
Source: NVD
CVE-2026-6125 MEDIUM - 6.3

A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injectio...

Vendor: maven
Product: org.dromara.warm:warm-flow-plugin-modes-sb
Published: Apr 12, 2026
Source: NVD
CVE-2026-6119 MEDIUM - 6.3

A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. ...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6118 MEDIUM - 6.3

A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulation of the argument command causes command injection. The attack is possible to be carried out remote...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6117 MEDIUM - 6.3

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload Endpoint. The manipulation of the argument File results in sandbox issue. The attack can be executed rem...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6111 MEDIUM - 6.3

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit h...

Vendor: pip
Product: metagpt
Published: Apr 12, 2026
Source: NVD
CVE-2026-6109 MEDIUM - 4.3

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack ma...

Vendor: pip
Product: metagpt
Published: Apr 12, 2026
Source: NVD