Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,121 - 7,140 of 13,554 CVEs
CVE-2026-2988 MEDIUM - 6.4

The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

Published: Apr 08, 2026
Source: NVD
CVE-2026-1163 MEDIUM - 4.1

An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests ...

Vendor: pip
Product: lollms
Published: Apr 08, 2026
Source: NVD
CVE-2026-32289 MEDIUM - 6.1

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied...

Vendor: Go standard library
Product: html/template
Published: Apr 08, 2026
Source: NVD
CVE-2026-32288 MEDIUM - 5.5

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Vendor: Go standard library
Product: archive/tar
Published: Apr 08, 2026
Source: NVD
CVE-2026-32282 MEDIUM - 6.4

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to av...

Vendor: Go standard library
Product: internal/syscall/unix
Published: Apr 08, 2026
Source: NVD
CVE-2025-14732 MEDIUM - 6.4

The Elementor Website Builder โ€“ More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

Vendor: elemntor
Product: Elementor Website Builder โ€“ more than just a page builder
Published: Apr 08, 2026
Source: NVD
CVE-2026-39413 MEDIUM - 4.2

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the jwt.decode() call does not explicitly ...

Vendor: pip
Product: lightrag-hku
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39410 MEDIUM - 4.8

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the...

Vendor: npm
Product: hono
Published: Apr 08, 2026
Source: GitHub

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause...

Vendor: npm
Product: hono
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39408 MEDIUM - 7.5

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially cra...

Vendor: npm
Product: hono
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39407 MEDIUM - 5.3

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used f...

Vendor: npm
Product: hono
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39406 MEDIUM - 5.3

@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, th...

Vendor: npm
Product: @hono/node-server
Published: Apr 08, 2026
Source: GitHub

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools

Vendor: npm
Product: openclaw-claude-bridge
Published: Apr 08, 2026
Source: GitHub
CVE-2026-4406 MEDIUM - 4.7

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comme...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4401 MEDIUM - 5.4

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This mak...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4394 MEDIUM - 6.1

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-2263 MEDIUM - 5.3

The Hustle โ€“ Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for un...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4065 MEDIUM - 5.4

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (whi...

Published: Apr 07, 2026
Source: NVD
CVE-2026-35406 MEDIUM - 6.2

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.

Vendor: containers
Product: aardvark-dns
Published: Apr 07, 2026
Source: NVD
CVE-2026-34371 MEDIUM - 6.3

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments using the default local file strategy, a malicious artifact filename containing traversal sequences (fo...

Vendor: danny-avila
Product: LibreChat
Published: Apr 07, 2026
Source: NVD