Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,658
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,841 - 6,860 of 13,554 CVEs
CVE-2026-5826 MEDIUM - 4.3

A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. The exploit has been published an...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5825 MEDIUM - 4.3

A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /delmemberinfo.php. Performing a manipulation of the argument userid results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may b...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5823 MEDIUM - 6.3

A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the argument Home causes sql injection. It is possible to initiate the attack remotely. The exploit has ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5812 MEDIUM - 5.4

A security flaw has been discovered in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Parameter Handler. Performing a manipulation of the argument txtqty results in business logic errors. It is possible to initiate ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5811 MEDIUM - 5.4

A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price leads to business logic errors. The attack may be performed ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4332 MEDIUM - 5.4

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers d...

Published: Apr 08, 2026
Source: NVD
CVE-2026-2619 MEDIUM - 4.3

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to inco...

Vendor: gitlab
Product: gitlab
Published: Apr 08, 2026
Source: NVD
CVE-2026-2104 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks.

Vendor: gitlab
Product: gitlab
Published: Apr 08, 2026
Source: NVD
CVE-2026-1752 MEDIUM - 4.3

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the ...

Vendor: gitlab
Product: gitlab
Published: Apr 08, 2026
Source: NVD
CVE-2026-1516 MEDIUM - 5.7

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.

Vendor: gitlab
Product: gitlab
Published: Apr 08, 2026
Source: NVD
CVE-2026-1101 MEDIUM - 6.5

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries.

Vendor: gitlab
Product: gitlab
Published: Apr 08, 2026
Source: NVD
CVE-2025-9484 MEDIUM - 4.3

GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.

Vendor: gitlab
Product: gitlab
Published: Apr 08, 2026
Source: NVD
CVE-2026-5919 MEDIUM - 6.5

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5918 MEDIUM - 4.3

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5911 MEDIUM - 4.3

Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5906 MEDIUM - 4.3

Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5905 MEDIUM - 6.5

Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5903 MEDIUM - 6.5

Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5901 MEDIUM - 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5900 MEDIUM - 4.3

Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD