Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
Showing 6,621 - 6,640 of 13,919 CVEs
CVE-2026-6119 MEDIUM - 6.3

A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. ...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6118 MEDIUM - 6.3

A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulation of the argument command causes command injection. The attack is possible to be carried out remote...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6117 MEDIUM - 6.3

A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload Endpoint. The manipulation of the argument File results in sandbox issue. The attack can be executed rem...

Published: Apr 12, 2026
Source: NVD
CVE-2026-6111 MEDIUM - 6.3

A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of the file metagpt/utils/common.py. The manipulation of the argument img_url_or_b64 results in server-side request forgery. It is possible to launch the attack remotely. The exploit h...

Vendor: pip
Product: metagpt
Published: Apr 12, 2026
Source: NVD
CVE-2026-6109 MEDIUM - 4.3

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack ma...

Vendor: pip
Product: metagpt
Published: Apr 12, 2026
Source: NVD
CVE-2026-6108 MEDIUM - 6.3

A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Model Context Protocol Node. Performing a manipulation results in os command injection. The attack is po...

Published: Apr 12, 2026
Source: NVD
CVE-2026-23900 MEDIUM - 6.5

Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.

Vendor: phoca.cz
Product: phoca.cz - Phoca Maps for Joomla
Published: Apr 11, 2026
Source: NVD
CVE-2026-5226 MEDIUM - 6.1

The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient output escaping on user-supplied URL paths in the get_current_url() function, which are inserted into Jav...

Published: Apr 11, 2026
Source: NVD
CVE-2026-5207 MEDIUM - 6.5

The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 9.2.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible ...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4979 MEDIUM - 5.0

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58. This is due to insufficient URL origin validation in the process_image_crop(...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4895 MEDIUM - 6.4

The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.8.9 This is due to insufficient input sanitization and output escaping in the gspb_greenShift_block_script_assets() function. The function uses st...

Published: Apr 11, 2026
Source: NVD
CVE-2026-3498 MEDIUM - 6.4

The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute in all versions up to, and including, 2.2.15. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit...

Published: Apr 11, 2026
Source: NVD
CVE-2026-3371 MEDIUM - 4.3

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authorization checks in the `save_course_content_order()` private method, which is called unconditionally by...

Published: Apr 11, 2026
Source: NVD
CVE-2026-3358 MEDIUM - 5.4

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, 3.9.7. This is due to missing post_status validation in the `enroll_now()` and `course_enrollment()` functions. Both enrollment endp...

Published: Apr 11, 2026
Source: NVD
CVE-2026-3691 MEDIUM - 5.3

OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that the target must initiate an OAuth authorization flow...

Published: Apr 11, 2026
Source: NVD
CVE-2026-3689 MEDIUM - 6.5

OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenClaw. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of the path...

Published: Apr 11, 2026
Source: NVD
CVE-2026-40199 MEDIUM - 6.5

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped addresses like ::ffff:192.168.1.1. This produces an 18 byte value inst...

Vendor: STIGTSP
Product: Net::CIDR::Lite
Published: Apr 10, 2026
Source: NVD
CVE-2026-33119 MEDIUM - 5.4

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: edge
Published: Apr 10, 2026
Source: NVD
CVE-2026-33118 MEDIUM - 4.3

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Vendor: microsoft
Product: edge_chromium
Published: Apr 10, 2026
Source: NVD

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endpoint accepted request...

Vendor: go
Product: go.temporal.io/server
Published: Apr 10, 2026
Source: NVD