Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,669
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,801 - 6,820 of 13,554 CVEs

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encoding it would incorrectly validate the byte length of the input string when performing a bounds check. ...

Vendor: bytecodealliance
Product: wasmtime
Published: Apr 09, 2026
Source: NVD
CVE-2026-40071 MEDIUM - 5.4

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This allows authenticated low-privileged users to execut...

Vendor: pyload
Product: pyload
Published: Apr 09, 2026
Source: NVD
CVE-2026-39985 MEDIUM - 4.3

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, the redirect parameter upon login to LORIS was not validating the value of the redirect as being within LORIS, wh...

Vendor: aces
Product: Loris
Published: Apr 09, 2026
Source: NVD
CVE-2026-39961 MEDIUM - 6.8

Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace โ€” production database credentials, API keys, s...

Vendor: aiven
Product: aiven-operator
Published: Apr 09, 2026
Source: NVD
CVE-2026-39315 MEDIUM - 6.1

Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documentation explicitly recommends for rendering user-supplied content in <head> safely. Internally, the hasDangerousProtocol() function in packages/unhead/src/plugins/safe.ts...

Vendor: unjs
Product: unhead
Published: Apr 09, 2026
Source: NVD
CVE-2026-35207 MEDIUM - 5.4

dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from ...

Vendor: linuxdeepin
Product: dde-control-center, deepin-deepinid-plugin
Published: Apr 09, 2026
Source: NVD
CVE-2025-70797 MEDIUM - 6.1

Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters.

Vendor: limesurvey
Product: limesurvey
Published: Apr 09, 2026
Source: NVD
CVE-2025-63238 MEDIUM - 6.1

A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the logged in user.

Vendor: limesurvey
Product: limesurvey
Published: Apr 09, 2026
Source: NVD
CVE-2026-40046 MEDIUM - 5.4

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT
Published: Apr 09, 2026
Source: NVD
CVE-2026-39943 MEDIUM - 6.5

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consistently calling the prepareDelta sanitization pipeline, sensit...

Vendor: directus
Product: directus
Published: Apr 09, 2026
Source: NVD
CVE-2026-39856 MEDIUM - 5.5

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When processing PE sections for page hashing, the function uses...

Vendor: mtrojnar
Product: osslsigncode
Published: Apr 09, 2026
Source: NVD
CVE-2026-39855 MEDIUM - 5.5

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When page hash processing is performed on a PE file, the functio...

Vendor: mtrojnar
Product: osslsigncode
Published: Apr 09, 2026
Source: NVD
CVE-2026-5960 MEDIUM - 4.3

A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploi...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4878 MEDIUM - 6.7

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-39941 MEDIUM - 6.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and EDesc parameters in EditEventAttendees.php to be rendered in a page without proper output encoding, enabling arbitrary JavaScript execution in victims�...

Vendor: ChurchCRM
Product: CRM
Published: Apr 09, 2026
Source: NVD
CVE-2026-35041 MEDIUM - 4.2

fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configured using a regular expression. Because the aud claim is attacker-controlled and the library evaluates it against the su...

Vendor: nearform
Product: fast-jwt
Published: Apr 09, 2026
Source: NVD
CVE-2026-35040 MEDIUM - 5.3

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options in verify functions can cause certain unintended behaviours. This is because some modifiers are statefu...

Vendor: nearform
Product: fast-jwt
Published: Apr 09, 2026
Source: NVD
CVE-2026-33005 MEDIUM - 4.3

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields ...

Vendor: Apache Software Foundation
Product: Apache OpenMeetings
Published: Apr 09, 2026
Source: NVD
CVE-2025-70365 MEDIUM - 5.4

A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative interfaces. An authenticated administrative user can inject arbitrary JavaScript code that is executed in the browser of users viewing the affected pa...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5959 MEDIUM - 6.6

A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory Reset Handler. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The complexit...

Published: Apr 09, 2026
Source: NVD