Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
Showing 7,161 - 7,180 of 13,544 CVEs
CVE-2026-39983 HIGH - 8.6

basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace(...

Vendor: npm
Product: basic-ftp
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39981 HIGH - 8.8

AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or d...

Vendor: pip
Product: agixt
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39974 HIGH - 8.5

n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and operations. Prior to 2.47.4, an authenticated Server-Side Request Forgery in n8n-mcp allows a caller holding a valid AUTH_TOKEN to cause the server to iss...

Vendor: npm
Product: n8n-mcp
Published: Apr 08, 2026
Source: GitHub

Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior to 0.22.0, a cache key collision vulnerability in TopicSelectorStore allows an attacker to poison the match result cache, potentially causing private updates to be delivered to una...

Vendor: go
Product: github.com/dunglas/mercure
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39959 HIGH - 7.1

Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to malicious D-Bus peers. A peer on the same bus can spoof signals by impersonating the owner of a well-known name, exhaust system resources or cause file descriptor spillover by sendi...

Vendor: nuget
Product: Tmds.DBus
Published: Apr 08, 2026
Source: GitHub
CVE-2026-35455 HIGH - 7.3

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR ov...

Vendor: immich-app
Product: immich
Published: Apr 08, 2026
Source: NVD
CVE-2026-35446 HIGH - 7.7

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping th...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-35401 HIGH - 7.5

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0a...

Vendor: saleor
Product: saleor
Published: Apr 08, 2026
Source: NVD
CVE-2026-35169 HIGH - 8.7

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result ...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-34723 HIGH - 7.5

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started endpoint to get access to sensitive internal entity data, even after the system setup was completed. This vulnerability is fixed in 7...

Vendor: zammad
Product: zammad
Published: Apr 08, 2026
Source: NVD
CVE-2026-34392 HIGH - 7.5

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can allow an attacker to traverse outside of the intended directory,...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-33350 HIGH - 7.5

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, a SQL injection has been identified in some code sections for the MRI feedback popup window of the imaging browse...

Vendor: aces
Product: Loris
Published: Apr 08, 2026
Source: NVD
CVE-2026-30818 HIGH - 8.0

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker to...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2026-30815 HIGH - 8.0

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification o...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2026-30814 HIGH - 8.0

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arb...

Vendor: TP-Link Systems Inc.
Product: AX53 v1.0
Published: Apr 08, 2026
Source: NVD
CVE-2025-50673 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50672 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50671 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time,...

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50670 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time parameters.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD
CVE-2025-50669 HIGH - 7.5

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.

Vendor: dlink
Product: di-8003_firmware
Published: Apr 08, 2026
Source: NVD