Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,638
Quick preset (or use dates below)
Clear Filters
Showing 7,141 - 7,160 of 13,544 CVEs
CVE-2026-5858 HIGH - 8.8

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-40036 HIGH - 7.5

Unfurl beforeΒ 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/visjs endpoint that expand to gigabytes, exhausting server memo...

Vendor: obsidianforensics
Product: unfurl
Published: Apr 08, 2026
Source: NVD
CVE-2026-40032 HIGH - 7.8

UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution pipeline where the _run_command() function passes constructed command strings directly to eval without proper sanitization. Attackers can inject shell...

Vendor: tclahr
Product: UAC
Published: Apr 08, 2026
Source: NVD
CVE-2026-40031 HIGH - 7.8

MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, including bare-name LoadLibraryU and dlopen calls without path qualification for vmmpyc, libMSCompression, and plugin DLLs. An attacker who places a malici...

Vendor: ufrisk
Product: MemProcFS
Published: Apr 08, 2026
Source: NVD
CVE-2026-40030 HIGH - 7.8

parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is passed unsanitized into an os.popen() shell command with ls, allowing arbitrary command injection via crafted volume path arguments containing shell metacharacters. An attacker can...

Vendor: khyrenz
Product: parseusbs
Published: Apr 08, 2026
Source: NVD
CVE-2026-40029 HIGH - 7.8

parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsanitized into an os.popen() shell command, allowing arbitrary command execution via crafted .lnk filenames containing shell metacharacters. An attacker can craft a .lnk filename wit...

Vendor: khyrenz
Product: parseusbs
Published: Apr 08, 2026
Source: NVD
CVE-2026-40027 HIGH - 7.3

ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses attacker-controlled file_name_from values from a database directly as the output filename, allowing arbitrary file writes outside the report output dire...

Vendor: abrignoni
Product: ALEAPP
Published: Apr 08, 2026
Source: NVD
CVE-2026-40024 HIGH - 7.1

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can cra...

Vendor: sleuthkit
Product: sleuthkit
Published: Apr 08, 2026
Source: NVD
CVE-2026-5805 HIGH - 7.3

A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available t...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5436 HIGH - 8.1

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's path_join() β€” a f...

Published: Apr 08, 2026
Source: NVD
CVE-2026-39891 HIGH - 8.8

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions ...

Vendor: MervinPraison
Product: PraisonAI
Published: Apr 08, 2026
Source: NVD
CVE-2026-39889 HIGH - 7.5

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. The create_a2u_routes() function registers the following endpoints with NO authentication checks: /a2u/info, /a2u/subscribe, /a2u/eve...

Vendor: MervinPraison
Product: PraisonAI
Published: Apr 08, 2026
Source: NVD
CVE-2026-39885 HIGH - 7.5

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAP...

Vendor: agentfront, @frontmcp, frontmcp
Product: frontmcp, adapters, sdk, mcp-from-openapi
Published: Apr 08, 2026
Source: NVD
CVE-2026-39883 HIGH - 7.0

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerabi...

Vendor: open-telemetry
Product: opentelemetry-go
Published: Apr 08, 2026
Source: NVD
CVE-2026-39414 HIGH - 6.5

MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO's S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader's nextSplit() fu...

Vendor: minio
Product: minio
Published: Apr 08, 2026
Source: NVD
CVE-2026-5802 HIGH - 7.3

A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation of the argument jarFilePath leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be...

Published: Apr 08, 2026
Source: NVD
CVE-2026-39863 HIGH - 7.5

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. Th...

Vendor: kamailio
Product: kamailio
Published: Apr 08, 2026
Source: NVD
CVE-2026-35478 HIGH - 8.3

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system β€” including administrators and superusers β€” by supplying the target's user ID in the user field of a POS...

Vendor: inventree
Product: InvenTree
Published: Apr 08, 2026
Source: NVD
CVE-2026-35476 HIGH - 7.2

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user ...

Vendor: inventree
Product: InvenTree
Published: Apr 08, 2026
Source: NVD
CVE-2026-23869 HIGH - 7.5

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered b...

Vendor: Meta
Product: react-server-dom-turbopack, react-server-dom-parcel, react-server-dom-webpack
Published: Apr 08, 2026
Source: NVD