Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,730
Quick preset (or use dates below)
Clear Filters
Showing 6,921 - 6,940 of 13,934 CVEs
CVE-2026-39392 MEDIUM - 5.5

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Pages module does not apply the html_purify validation rule to content fields during create and update operations, while the Blog modul...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 08, 2026
Source: NVD
CVE-2026-39391 MEDIUM - 4.8

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the blacklist (ban) note parameter in UserController::ajax_blackList_post() is stored in the database without sanitization and rendered int...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 08, 2026
Source: NVD
CVE-2026-39390 MEDIUM - 5.5

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps iframe setting (cMap field) in compInfosPost() sanitizes input using strip_tags() with an <iframe> allowlist and rege...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 08, 2026
Source: NVD
CVE-2026-39389 MEDIUM - 6.7

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is fixed in 0.31.4.0.

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 08, 2026
Source: NVD
CVE-2026-39859 MEDIUM - 7.5

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that boundary. A Liquid instance configured with an empty te...

Vendor: npm
Product: liquidjs
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39412 MEDIUM - 5.3

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropertyOnly security option, allowing template authors to extract values of prototype-inherited properties through a sorting side-channel attack. Application...

Vendor: npm
Product: liquidjs
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39411 MEDIUM - 5.0

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentication layer trusts a client-controlled X-lobe-chat-auth header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key i...

Vendor: npm
Product: @lobehub/lobehub
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39844 MEDIUM - 5.9

NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern ...

Vendor: pip
Product: nicegui
Published: Apr 08, 2026
Source: GitHub
CVE-2026-33753 MEDIUM - 6.2

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic ...

Vendor: pip
Product: rfc3161-client
Published: Apr 08, 2026
Source: GitHub
CVE-2026-35023 MEDIUM - 4.3

Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other us...

Vendor: Cloud Solutions SAS
Product: Wimi Teamwork
Published: Apr 08, 2026
Source: NVD
CVE-2026-2509 MEDIUM - 6.4

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering ...

Published: Apr 08, 2026
Source: NVD
CVE-2025-58713 MEDIUM - 6.4

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, ...

Vendor: Red Hat
Product: Red Hat Process Automation 7
Published: Apr 08, 2026
Source: NVD
CVE-2025-57854 MEDIUM - 6.4

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, eve...

Vendor: Red Hat
Product: Red Hat OpenShift Update Service
Published: Apr 08, 2026
Source: NVD
CVE-2025-57853 MEDIUM - 6.4

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root use...

Vendor: Red Hat
Product: Red Hat Web Terminal
Published: Apr 08, 2026
Source: NVD
CVE-2025-57851 MEDIUM - 6.4

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, ...

Vendor: Red Hat
Product: Multicluster Engine for Kubernetes
Published: Apr 08, 2026
Source: NVD
CVE-2025-57847 MEDIUM - 6.4

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container,...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Apr 08, 2026
Source: NVD

A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those t...

Vendor: pip
Product: pretix
Published: Apr 08, 2026
Source: NVD
CVE-2026-5302 MEDIUM - 6.3

CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites

Published: Apr 08, 2026
Source: NVD
CVE-2026-5300 MEDIUM - 5.9

Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests

Published: Apr 08, 2026
Source: NVD
CVE-2026-27102 MEDIUM - 6.6

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

Vendor: Dell
Product: PowerScale OneFS
Published: Apr 08, 2026
Source: NVD