Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,801 - 6,820 of 12,776 CVEs
CVE-2026-31790 HIGH - 7.5

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-28390 HIGH - 7.5

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial ...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-28389 HIGH - 7.5

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of S...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-28388 HIGH - 7.5

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. ...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-35533 HIGH - 7.7

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and ...

Vendor: jdx
Product: mise
Published: Apr 07, 2026
Source: NVD
CVE-2026-34045 HIGH - 8.2

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limi...

Vendor: podman-desktop
Product: podman-desktop
Published: Apr 07, 2026
Source: NVD
CVE-2026-29181 HIGH - 7.5

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, e...

Vendor: open-telemetry
Product: opentelemetry-go
Published: Apr 07, 2026
Source: NVD
CVE-2026-5741 HIGH - 7.3

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5739 HIGH - 7.3

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed r...

Vendor: maven
Product: tech.powerjob:powerjob-server-starter
Published: Apr 07, 2026
Source: NVD
CVE-2026-39376 HIGH - 7.5

FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns an HTML page containing a <meta http-equiv="refresh"> tag, it recursively calls itself with the redirect URL โ€” with no depth limit, no visited-URL deduplication, an...

Vendor: kagisearch
Product: fastfeedparser
Published: Apr 07, 2026
Source: NVD
CVE-2026-39371 HIGH - 8.1

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger stat...

Vendor: redwoodjs
Product: sdk
Published: Apr 07, 2026
Source: NVD
CVE-2026-39370 HIGH - 7.1

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm to bypass SSRF validation. The server then fetche...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD
CVE-2026-39369 HIGH - 7.6

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose server-local files through the GIF poster storage p...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD
CVE-2026-39361 HIGH - 7.7

OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichment_table/mod.rs fails to block IPv6 addresses because Rust's url crate returns them with surrounding brackets (e.g. "[::1]" not ":...

Vendor: openobserve
Product: openobserve
Published: Apr 07, 2026
Source: NVD
CVE-2026-39356 HIGH - 7.5

Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or back...

Vendor: drizzle-team
Product: drizzle-orm
Published: Apr 07, 2026
Source: NVD
CVE-2026-39322 HIGH - 8.8

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. That session is then accepted across authenticated /api routes, enabling account data access and authen...

Vendor: polarnl
Product: PolarLearn
Published: Apr 07, 2026
Source: NVD
CVE-2026-32864 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.ย  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file...

Vendor: NI
Product: LabVIEW
Published: Apr 07, 2026
Source: NVD
CVE-2026-32863 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.ย  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially cr...

Vendor: NI
Product: LabVIEW
Published: Apr 07, 2026
Source: NVD
CVE-2026-32862 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.ย  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI...

Vendor: NI
Product: LabVIEW
Published: Apr 07, 2026
Source: NVD
CVE-2026-32861 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW.ย  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted ....

Vendor: NI
Product: LabVIEW
Published: Apr 07, 2026
Source: NVD