Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,221 - 7,240 of 12,781 CVEs
CVE-2026-5032 HIGH - 7.5

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which caus...

Published: Apr 02, 2026
Source: NVD
CVE-2026-0686 HIGH - 7.2

The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_authorpage' function via the 'Receiver::post' function. This makes it possible for unauthenticated attackers to make web requests to arb...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5322 HIGH - 7.3

A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. Th...

Published: Apr 02, 2026
Source: NVD
CVE-2026-4347 HIGH - 8.1

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for un...

Published: Apr 02, 2026
Source: NVD
CVE-2026-1540 HIGH - 7.2

The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header

Published: Apr 02, 2026
Source: NVD
CVE-2026-5320 HIGH - 7.3

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of the component Chat API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-21765 HIGH - 8.8

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.ย  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

Vendor: HCLSoftware
Product: BigFix Platform
Published: Apr 02, 2026
Source: NVD
CVE-2026-34828 HIGH - 7.1

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued authenticated sessions to remain valid after sensitive account security changes, specifically password reset and passwor...

Vendor: go
Product: github.com/knadh/listmonk
Published: Apr 01, 2026
Source: GitHub

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who ...

Vendor: npm
Product: @nocobase/plugin-workflow-sql
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34783 HIGH - 8.1

Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function allows a malicious website to write arbitrary files to the filesystem of the machine running Ferret. When an operator scrapes a we...

Vendor: go
Product: github.com/MontFerret/ferret/v2
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34954 HIGH - 8.6

PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach ...

Vendor: pip
Product: praisonaiagents
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34955 HIGH - 8.8

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.run() with shell=True and relies solely on string-pattern matching to block dangerous commands. The blocklist does not include sh or bash as standalone ...

Vendor: pip
Product: praisonai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34940 HIGH - 8.7

KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/modelcontroller/engine_ollama.go constructs a shell command string using fmt.Sprintf with unsanitized model URL components (ref, modelParam). This shell command is executed via bas...

Vendor: go
Product: github.com/kubeai-project/kubeai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34936 HIGH - 7.7

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a caller-controlled api_base parameter that is concatenated with endpoint and passed directly to httpx.Client.request() when the litellm primary path raises AttributeError. No URL s...

Vendor: pip
Product: praisonai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34937 HIGH - 7.8

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-controlled code into python3 -c "<code>" and passing it to subprocess.run(..., shell=True). The escaping logic only handles \ and "...

Vendor: pip
Product: praisonaiagents
Published: Apr 01, 2026
Source: GitHub
CVE-2026-32929 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32928 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32927 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32926 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32925 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD