Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,781 - 6,800 of 12,776 CVEs
CVE-2026-39466 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blind SQL Injection.This issue affects Broken Link Checker: from n/a through <= 2.4.7.

Vendor: WPMU DEV - Your All-in-One WordPress Platform
Product: Broken Link Checker
Published: Apr 08, 2026
Source: NVD
CVE-2026-33088 HIGH - 7.3

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

Vendor: Six Apart Ltd.
Product: Movable Type, Movable Type Advanced, Movable Type Premium, Movable Type Premium Advanced Edition, Movable Type Premium (MT8-based)
Published: Apr 08, 2026
Source: NVD
CVE-2026-4808 HIGH - 7.2

The Gerador de Certificados โ€“ DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moveUploadedFile() function in all versions up to, and including, 1.3.6. This makes it possible for authenticated attackers, with Administrator-level access a...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4338 HIGH - 7.5

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts

Vendor: automattic
Product: activitypub
Published: Apr 08, 2026
Source: NVD
CVE-2026-24913 HIGH - 8.8

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.

Vendor: ICZ Corporation
Product: MATCHA INVOICE
Published: Apr 08, 2026
Source: NVD
CVE-2026-5726 HIGH - 7.8

ASDA-Soft Stack-based Buffer Overflow Vulnerability

Vendor: deltaww
Product: asda_soft
Published: Apr 08, 2026
Source: NVD
CVE-2026-3499 HIGH - 8.8

The Product Feed PRO for WooCommerce by AdTribes โ€“ Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2.1. This is due to missing or incorrect nonce validation on the ajax_migrate_to_custom_post_type, ajax_adt_clear_custom_a...

Published: Apr 08, 2026
Source: NVD
CVE-2026-33810 HIGH - 7.5

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Root...

Vendor: Go standard library
Product: crypto/x509
Published: Apr 08, 2026
Source: NVD
CVE-2026-32283 HIGH - 7.5

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Vendor: Go standard library
Product: crypto/tls
Published: Apr 08, 2026
Source: NVD
CVE-2026-32281 HIGH - 7.5

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptio...

Vendor: Go standard library
Product: crypto/x509
Published: Apr 08, 2026
Source: NVD
CVE-2026-32280 HIGH - 7.5

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

Vendor: Go standard library
Product: crypto/x509
Published: Apr 08, 2026
Source: NVD
CVE-2026-27144 HIGH - 7.1

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime.

Vendor: Go toolchain
Product: cmd/compile
Published: Apr 08, 2026
Source: NVD
CVE-2026-27140 HIGH - 8.8

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

Vendor: Go toolchain
Product: cmd/go
Published: Apr 08, 2026
Source: NVD
CVE-2026-4788 HIGH - 8.4

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.

Vendor: ibm
Product: tivoli_netcool\/impact
Published: Apr 08, 2026
Source: NVD
CVE-2026-3357 HIGH - 8.8

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

Vendor: langflow
Product: langflow
Published: Apr 08, 2026
Source: NVD
CVE-2026-1343 HIGH - 7.2

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are pr...

Vendor: ibm
Product: security_verify_access
Published: Apr 08, 2026
Source: NVD
CVE-2026-5747 HIGH - 7.5

An out-of-bounds write issue in the virtio PCI transport in Amazon Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-1342 HIGH - 8.5

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from o...

Vendor: ibm
Product: security_verify_access
Published: Apr 08, 2026
Source: NVD
CVE-2026-35568 HIGH - 5.7

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or n...

Vendor: modelcontextprotocol
Product: java-sdk
Published: Apr 07, 2026
Source: NVD
CVE-2026-34079 HIGH - 7.5

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the...

Vendor: flatpak
Product: flatpak
Published: Apr 07, 2026
Source: NVD