Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,638
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 7,181 - 7,200 of 13,554 CVEs
CVE-2026-34765 MEDIUM - 6.0

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing ...

Vendor: npm
Product: electron
Published: Apr 07, 2026
Source: GitHub
CVE-2026-5384 MEDIUM - 5.8

An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This is...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5383 MEDIUM - 4.4

An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This issue was fixed in vers...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5380 MEDIUM - 5.3

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Medium...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5378 MEDIUM - 5.8

An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8 Medium). This issue was fixe...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5376 MEDIUM - 5.9

An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N (5...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5374 MEDIUM - 5.8

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). Thi...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5372 MEDIUM - 6.4

An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H...

Published: Apr 07, 2026
Source: NVD
CVE-2026-35484 MEDIUM - 5.3

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_preset() allows reading any .yaml file on the server filesystem. The parsed YAML key-value pairs (including passwords, API keys, connection s...

Vendor: oobabooga
Product: text-generation-webui
Published: Apr 07, 2026
Source: NVD
CVE-2026-35483 MEDIUM - 5.3

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_template() allows reading files with .jinja, .jinja2, .yaml, or .yml extensions from anywhere on the server filesystem. For .jinja files the ...

Vendor: oobabooga
Product: text-generation-webui
Published: Apr 07, 2026
Source: NVD
CVE-2026-35462 MEDIUM - 4.3

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key β€” regardless of its expiration date β€” is accepted indefinitely, allowing a user whose key has expired t...

Vendor: papra-hq
Product: papra
Published: Apr 07, 2026
Source: NVD
CVE-2026-35461 MEDIUM - 5.0

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows authenticated users to register arbitrary URLs as webhook endpoints with no validation of the destination address. The server makes outbound HTTP POST requests to registered URLs, inc...

Vendor: papra-hq
Product: papra
Published: Apr 07, 2026
Source: NVD
CVE-2026-35460 MEDIUM - 4.3

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Papra interpolate user.name directly into HTML without escaping or sanitization. An attacker who registers with a display name containing HTML tags will have those tags injected into...

Vendor: papra-hq
Product: papra
Published: Apr 07, 2026
Source: NVD
CVE-2026-33033 MEDIUM - 6.5

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such as...

Vendor: djangoproject
Product: Django
Published: Apr 07, 2026
Source: NVD
CVE-2026-3466 MEDIUM - 5.4

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows an attacker with dashboard creation privileges to perform stored cross-site scripting (XSS) attacks by trick...

Vendor: checkmk
Product: checkmk
Published: Apr 07, 2026
Source: NVD

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to acce...

Vendor: Mlflow
Product: Mlflow
Published: Apr 07, 2026
Source: NVD

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows action...

Vendor: Mlflow
Product: Mlflow
Published: Apr 07, 2026
Source: NVD
CVE-2026-34903 MEDIUM - 5.4

Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.

Vendor: OceanWP
Product: Ocean Extra
Published: Apr 07, 2026
Source: NVD
CVE-2026-34899 MEDIUM - 5.3

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.

Vendor: Eniture technology
Product: LTL Freight Quotes – Worldwide Express Edition
Published: Apr 07, 2026
Source: NVD
CVE-2026-33227 MEDIUM - 4.3

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authentica...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ Web
Published: Apr 07, 2026
Source: NVD