Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,640
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,141 - 7,160 of 13,554 CVEs
CVE-2026-34080 MEDIUM - 5.5

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar case...

Vendor: flatpak
Product: xdg-dbus-proxy
Published: Apr 07, 2026
Source: NVD
CVE-2026-32712 MEDIUM - 5.4

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-tabl...

Vendor: opensourcepos
Product: opensourcepos
Published: Apr 07, 2026
Source: NVD
CVE-2026-39395 MEDIUM - 4.3

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached sign...

Vendor: sigstore
Product: cosign
Published: Apr 07, 2026
Source: NVD

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protected via the protectedFields server option. Any auth...

Vendor: parse-community
Product: parse-server
Published: Apr 07, 2026
Source: NVD
CVE-2026-39380 MEDIUM - 5.4

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through...

Vendor: opensourcepos
Product: opensourcepos
Published: Apr 07, 2026
Source: NVD
CVE-2026-39374 MEDIUM - 6.5

Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of ANY issue across the entire Plane instance, regardless of workspace or project membership. The endpoint fetches is...

Vendor: makeplane
Product: plane
Published: Apr 07, 2026
Source: NVD
CVE-2026-39373 MEDIUM - 5.3

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the ...

Vendor: latchset
Product: jwcrypto
Published: Apr 07, 2026
Source: NVD
CVE-2026-39368 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamers. The vulnerable flow allowed a low-privilege use...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD
CVE-2026-39367 MEDIUM - 5.4

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a video'...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD
CVE-2026-39366 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate their wallet balance and renew subscriptions. The...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD
CVE-2026-39360 MEDIUM - 4.3

RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket can still exfiltrate victim objects by copying them into an at...

Vendor: rustfs
Product: rustfs
Published: Apr 07, 2026
Source: NVD
CVE-2026-39354 MEDIUM - 6.5

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question by supplying that question's public ID as the postId parameter to POST /ques...

Vendor: Erudika
Product: scoold
Published: Apr 07, 2026
Source: NVD
CVE-2026-39348 MEDIUM - 4.3

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits authorization on job specification and vacancy attachment download handlers, allowing authenticated low-privilege users to read attachments via direct reference to attachment identifiers...

Vendor: orangehrm
Product: orangehrm
Published: Apr 07, 2026
Source: NVD
CVE-2026-39346 MEDIUM - 5.4

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass disabled-module access controls via URL-encoded request paths and access functionality of modules disabled by an administrator. This vulnerability is fixe...

Vendor: orangehrm
Product: orangehrm
Published: Apr 07, 2026
Source: NVD
CVE-2026-39345 MEDIUM - 4.9

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary local files. This vuln...

Vendor: orangehrm
Product: orangehrm
Published: Apr 07, 2026
Source: NVD
CVE-2026-39338 MEDIUM - 6.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied input prior to rendering it within the browser'...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39336 MEDIUM - 6.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields set from config, Person editor defaults rendered into address fields, and external self-registration form defaults. This is primarily an admin-to-admin ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39335 MEDIUM - 6.1

ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. This is primarily an admin-to-admin stored XSS path when writable entity fields are abused. This vulnerability is fixed in 7.1.1.

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the ser...

Vendor: parse-community
Product: parse-server
Published: Apr 07, 2026
Source: NVD
CVE-2026-35572 MEDIUM - 6.0

ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (SSRF) by supplying a crafted URL in the Referer request header. The server subsequently makes an outbound request to the attacker-controlled domain, con...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD