Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,241 - 7,260 of 12,781 CVEs
CVE-2026-34752 HIGH - 7.5

Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the Haraka worker process. This issue has been patched in version 3.1.4.

Vendor: npm
Product: Haraka
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34728 HIGH - 8.7

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied name parameter is concatenated with the base upload directory path without any pa...

Vendor: composer
Product: phpmyfaq/phpmyfaq
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34725 HIGH - 8.3

DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another user's browser; in...

Vendor: npm
Product: dbgate-web
Published: Apr 01, 2026
Source: GitHub

Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary file write with the privileges of the Poetry process. It is reachable from untrusted package artifact...

Vendor: pip
Product: poetry
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34572 HIGH - 8.8

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34570 HIGH - 8.8

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend des...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34524 HIGH - 8.3

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in chat endpoints allows an authenticated attacker to read an...

Vendor: npm
Product: sillytavern
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34522 HIGH - 8.1

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in /api/chats/import allows an authenticated attacker to writ...

Vendor: npm
Product: sillytavern
Published: Apr 01, 2026
Source: GitHub
CVE-2026-4101 HIGH - 8.1

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 under certain load conditions could allow an attacker to bypass authenticati...

Vendor: ibm
Product: security_verify_access
Published: Apr 01, 2026
Source: NVD
CVE-2026-34545 HIGH - 7.3

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write control...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 01, 2026
Source: NVD
CVE-2026-34544 HIGH - 7.3

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_deco...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 01, 2026
Source: NVD
CVE-2026-34543 HIGH - 7.5

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). T...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 01, 2026
Source: NVD
CVE-2026-1345 HIGH - 7.3

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow an unauthenticated user to execute arbitrary commands as lower u...

Vendor: ibm
Product: security_verify_access
Published: Apr 01, 2026
Source: NVD
CVE-2026-34742 HIGH - 8.1

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPHandler or SSE...

Vendor: go
Product: github.com/modelcontextprotocol/go-sdk
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34581 HIGH - 8.1

goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2.

Vendor: go
Product: github.com/patrickhener/goshs
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34748 HIGH - 8.7

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in the admin panel. An authenticated user with write access to a collection could save content that, when viewed by another use...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD
CVE-2026-34747 HIGH - 8.5

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections. This issue has been patched i...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD
CVE-2026-34746 HIGH - 7.7

Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the upload functionality. Authenticated users with create or update access to an upload-enabled collection could cause the server...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD
CVE-2026-33544 HIGH - 7.7

Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on singleton instances shared across all concurrent re...

Vendor: go
Product: github.com/steveiliop56/tinyauth
Published: Apr 01, 2026
Source: GitHub
CVE-2026-29782 HIGH - 7.2

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It loads a record from the zz_oauth2 table using the attacker-controlled GET paramete...

Vendor: composer
Product: devcode-it/openstamanager
Published: Apr 01, 2026
Source: GitHub