Total CVEs

125,674

Critical Severity

2,261

High Severity

7,825

Last 7 Days

1,174
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 681 - 700 of 22,079 CVEs
CVE-2026-7022 HIGH - 7.3

A security vulnerability has been detected in SmythOS sre up to 0.0.15. Affected is the function AgentRuntime of the file packages/core/src/subsystems/AgentManager/AgentRuntime.class.ts of the component HTTP Header Handler. Such manipulation of the argument X-DEBUG-RUN/X-DEBUG-INJ leads to improper ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7021 LOW - 3.5

A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/src/LLM/utils.ts of the component Connector Service. This manipulation of the argument baseURL causes information disclosure. It is possible to initiate the attack remotely. The expl...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7020 MEDIUM - 5.6

A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. T...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7019 HIGH - 8.8

A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly availa...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7018 MEDIUM - 5.6

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argu...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7016 LOW - 2.4

A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could...

Published: Apr 26, 2026
Source: NVD
CVE-2026-42255 HIGH - 7.2

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

Vendor: Technitium
Product: DnsServer
Published: Apr 26, 2026
Source: NVD
CVE-2026-7015 LOW - 2.4

A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7014 LOW - 2.4

A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7013 LOW - 2.4

A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated remotely. The exploit ha...

Published: Apr 26, 2026
Source: NVD
CVE-2026-42254 MEDIUM - 4.0

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

Vendor: Hickory Project
Product: Hickory DNS
Published: Apr 26, 2026
Source: NVD
CVE-2026-7012 LOW - 2.4

A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to versio...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7011 LOW - 2.4

A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a manipulation of the argument f_logging_file can lead to cross site scripting. It is possible to launc...

Published: Apr 26, 2026
Source: NVD
CVE-2026-41572 MEDIUM - 5.3

Note Mark: Unauthenticated read of notes and assets in soft-deleted public books

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-41571 CRITICAL - 9.4

Note Mark: OIDC-registered users authenticated by submitting password "null"

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-41520 HIGH - 7.9

Cillium exposes sensitive information included in the cilium-bugtool debug archive

Vendor: go
Product: github.com/cilium/cilium
Published: Apr 25, 2026
Source: GitHub
CVE-2026-7002 HIGH - 7.3

A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the at...

Published: Apr 25, 2026
Source: NVD
CVE-2026-7001 LOW - 2.4

A vulnerability was found in Datacom DM4100 1.3.6.1.4.1.3709. This affects an unknown part of the component Ethernet Configuration Page. Performing a manipulation of the argument Name results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public an...

Published: Apr 25, 2026
Source: NVD
CVE-2026-7000 LOW - 2.4

A vulnerability has been found in Datacom DM4100 1.3.6.1.4.1.3709. Affected by this issue is some unknown functionality of the component VLAN Page. Such manipulation of the argument VLAN Name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to th...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6999 LOW - 2.4

A flaw has been found in BIVOCOM TR321 21.1.1.50. Affected by this vulnerability is an unknown functionality of the component Wireless Setting. This manipulation of the argument Network Name SSID causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been pub...

Published: Apr 25, 2026
Source: NVD