Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,269
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 7,161 - 7,180 of 12,780 CVEs
CVE-2026-34833 HIGH - 7.5

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue ha...

Vendor: bulwarkmail
Product: webmail
Published: Apr 02, 2026
Source: NVD
CVE-2023-7343 HIGH - 7.8

HiSecOS web server versions 05.0.00 to 08.3.01 prior to 08.3.02 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5429 HIGH - 7.8

Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5418 HIGH - 7.3

A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of the file app/server/appsmith-interfaces/src/main/java/com/appsmith/util/WebClientUtils.java of the component Dashboard. Such manipulation leads to server-side request forgery. The at...

Published: Apr 02, 2026
Source: NVD
CVE-2026-34426 HIGH - 7.6

OpenClaw versions prior to commit b57b680Β contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment variables into execution without approval system validation. At...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 02, 2026
Source: NVD
CVE-2025-43264 HIGH - 8.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43257 HIGH - 8.7

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43219 HIGH - 8.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43202 HIGH - 8.8

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.

Vendor: Apple
Product: iOS and iPadOS, macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44303 HIGH - 7.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the file system.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44286 HIGH - 7.5

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44250 HIGH - 8.2

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44219 HIGH - 7.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be able to access private information.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-40858 HIGH - 7.1

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user consent.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-40849 HIGH - 7.5

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2023-7342 HIGH - 8.8

HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit this flaw t...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5368 HIGH - 7.3

A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-34827 HIGH - 7.5

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition: form-data; name="..." using repeated String#index searches combined w...

Vendor: rack
Product: rack
Published: Apr 02, 2026
Source: NVD
CVE-2026-34577 HIGH - 8.6

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies the full HTTP response back to the caller. The only validation is url.endsWith('mp4'), which is trivially bypas...

Vendor: gitroomhq
Product: postiz-app
Published: Apr 02, 2026
Source: NVD
CVE-2026-34576 HIGH - 7.7

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint accepts a user-supplied URL and fetches it server-side using axios.get() with no SSRF protections. The only validation is a file extension check (.png, .jpg, etc.) which is trivially b...

Vendor: gitroomhq
Product: postiz-app
Published: Apr 02, 2026
Source: NVD