Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,413
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,701 - 6,720 of 12,776 CVEs
CVE-2026-35455 HIGH - 7.3

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR ov...

Vendor: immich-app
Product: immich
Published: Apr 08, 2026
Source: NVD
CVE-2026-35446 HIGH - 7.7

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping th...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-35401 HIGH - 7.5

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0a...

Vendor: saleor
Product: saleor
Published: Apr 08, 2026
Source: NVD
CVE-2026-35169 HIGH - 8.7

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result ...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-34723 HIGH - 7.5

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started endpoint to get access to sensitive internal entity data, even after the system setup was completed. This vulnerability is fixed in 7...

Vendor: zammad
Product: zammad
Published: Apr 08, 2026
Source: NVD
CVE-2026-34392 HIGH - 7.5

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can allow an attacker to traverse outside of the intended directory,...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-33350 HIGH - 7.5

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, a SQL injection has been identified in some code sections for the MRI feedback popup window of the imaging browse...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-30818 HIGH - 8.0

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker to...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2026-30815 HIGH - 8.0

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification o...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2026-30814 HIGH - 8.0

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arb...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2025-50673 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50672 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50671 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time,...

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50670 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time parameters.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50669 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50668 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50667 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50666 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50665 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, time, mem_gb2312, and mem_utf8 parameters.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50664 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD