Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,730
Quick preset (or use dates below)
Clear Filters
Showing 6,901 - 6,920 of 13,934 CVEs
CVE-2026-35407 MEDIUM - 6.5

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and authorization flaw was found in the account email change workflow, the confirmation flow did not verify that the email change confirmation token was issued for the given authenticat...

Vendor: saleor
Product: saleor
Published: Apr 08, 2026
Source: NVD
CVE-2026-35403 MEDIUM - 6.5

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 and 28.0.1, there is a potential for a cross-site scripting attack in the survey_accounts module if a user provid...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-35165 MEDIUM - 6.3

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 and 28.0.1, while the document_repository frontend was restricting file access, the backend endpoint was not cor...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-34985 MEDIUM - 6.3

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the ba...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-34719 MEDIUM - 4.3

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was missing a proper validation for loop back addresses, or link-local addresses — only the URL scheme (HTTP/HTTPS) as well as the hostname was checked. This could end up in retrieving con...

Vendor: zammad
Product: zammad
Published: Apr 08, 2026
Source: NVD
CVE-2026-30817 MEDIUM - 5.7

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, pote...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2026-30816 MEDIUM - 5.7

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, po...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2026-20709 MEDIUM - 6.6

Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-0814 MEDIUM - 4.3

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-leve...

Published: Apr 08, 2026
Source: NVD
CVE-2026-0811 MEDIUM - 5.4

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated atta...

Published: Apr 08, 2026
Source: NVD
CVE-2025-30650 MEDIUM - 6.7

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to line cards running Junos OS Evolved as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line...

Vendor: Juniper Networks
Product: Junos OS
Published: Apr 08, 2026
Source: NVD
CVE-2026-33459 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple such requests are sent ...

Vendor: Elastic
Product: Kibana
Published: Apr 08, 2026
Source: NVD
CVE-2026-33458 MEDIUM - 6.3

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

Vendor: Elastic
Product: Kibana
Published: Apr 08, 2026
Source: NVD
CVE-2026-32591 MEDIUM - 5.2

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An at...

Vendor: Red Hat
Product: mirror registry for Red Hat OpenShift, mirror registry for Red Hat OpenShift 2, Red Hat Quay 3
Published: Apr 08, 2026
Source: NVD
CVE-2026-4837 MEDIUM - 6.6

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is u...

Published: Apr 08, 2026
Source: NVD
CVE-2026-33460 MEDIUM - 4.3

Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces through an internal enrollment endpoint. The endpoi...

Vendor: Elastic
Product: Kibana
Published: Apr 08, 2026
Source: NVD
CVE-2026-2377 MEDIUM - 6.5

A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by providing a specially crafted web address (URL). This allows the application's backend to make arbitrary requests to internal network resources, a vulnerability known as Server-Side Request Forgery (S...

Published: Apr 08, 2026
Source: NVD
CVE-2025-57175 MEDIUM - 6.4

Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.

Vendor: Siklu
Product: EtherHaul 8010
Published: Apr 08, 2026
Source: NVD
CVE-2025-14243 MEDIUM - 5.3

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.

Vendor: Red Hat
Product: mirror registry for Red Hat OpenShift, mirror registry for Red Hat OpenShift 2
Published: Apr 08, 2026
Source: NVD
CVE-2026-39865 MEDIUM - 5.9

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exist...

Vendor: axios
Product: axios
Published: Apr 08, 2026
Source: NVD