Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,734
Quick preset (or use dates below)
Clear Filters
Showing 6,881 - 6,900 of 13,934 CVEs
CVE-2026-5864 MEDIUM - 6.5

Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5808 MEDIUM - 4.3

A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an unknown function of the file apps/dashboard/src/app/(dashboard)/onboarding/client.tsx of the component Onboarding Endpoint. The manipulation of the argument callbackURL results in ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5711 MEDIUM - 6.4

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-40037 MEDIUM - 6.5

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unint...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 08, 2026
Source: NVD
CVE-2026-40028 MEDIUM - 5.4

Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allows an attacker to execute arbitrary JavaScript when a user scans JSON-exported logs containing malicious content in the Computer field. An attacker can inject JavaScript into the Co...

Vendor: Yamato-Security
Product: hayabusa
Published: Apr 08, 2026
Source: NVD
CVE-2026-40026 MEDIUM - 4.4

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed...

Vendor: sleuthkit
Product: sleuthkit
Published: Apr 08, 2026
Source: NVD
CVE-2026-40025 MEDIUM - 4.4

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap reads past the allocated buffer. An attacker can craft a malicious APFS d...

Vendor: sleuthkit
Product: sleuthkit
Published: Apr 08, 2026
Source: NVD
CVE-2026-39901 MEDIUM - 5.7

monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transactions through the transaction update endpoint, despite the application explicitly blocking deletion ...

Vendor: monetr
Product: monetr
Published: Apr 08, 2026
Source: NVD
CVE-2026-40087 MEDIUM - 5.3

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same at...

Vendor: pip
Product: langchain-core
Published: Apr 08, 2026
Source: GitHub
CVE-2026-5803 MEDIUM - 6.3

A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. Performing a manipulation of the argument Query results in server-side request forge...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5451 MEDIUM - 6.4

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions up to, and including, 4.14. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...

Published: Apr 08, 2026
Source: NVD
CVE-2026-39892 MEDIUM - 9.8

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in ...

Vendor: pyca
Product: cryptography
Published: Apr 08, 2026
Source: NVD
CVE-2026-39882 MEDIUM - 5.3

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-...

Vendor: open-telemetry
Product: opentelemetry-go
Published: Apr 08, 2026
Source: NVD
CVE-2026-39881 MEDIUM - 5.0

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol m...

Vendor: vim
Product: vim
Published: Apr 08, 2026
Source: NVD
CVE-2026-39416 MEDIUM - 6.1

AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled c...

Vendor: ail-project
Product: ail-framework
Published: Apr 08, 2026
Source: NVD
CVE-2026-39415 MEDIUM - 4.3

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vulnerability has been identified in Frappe Learning where quiz scores can be modified by students before submission. The application currently relies on client-side calculated s...

Vendor: frappe
Product: lms
Published: Apr 08, 2026
Source: NVD
CVE-2026-39880 MEDIUM - 5.0

Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the HWID device registration logic allows an authenticated user to bypass the configured limit for HWID devices and register more devices than expected, allowing them to resell subscrip...

Vendor: remnawave
Product: backend
Published: Apr 08, 2026
Source: NVD
CVE-2026-39864 MEDIUM - 4.4

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted SIP packet if a successful user ...

Vendor: kamailio
Product: kamailio
Published: Apr 08, 2026
Source: NVD
CVE-2026-35479 MEDIUM - 6.6

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requirement is out of alignment with other plugin actions (...

Vendor: inventree
Product: InvenTree
Published: Apr 08, 2026
Source: NVD
CVE-2026-35477 MEDIUM - 5.5

InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Environ...

Vendor: inventree
Product: InvenTree
Published: Apr 08, 2026
Source: NVD