Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,241 - 7,260 of 13,554 CVEs

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-Sent Events text protocol output without sanitizing newline characters (\r, \n). Since the SSE protocol treats both \r an...

Vendor: npm
Product: @nestjs/core
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35492 MEDIUM - 6.5

Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a part...

Vendor: pip
Product: kedro-datasets
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35201 MEDIUM - 5.9

Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than INT_MAX are truncated to a signed int before entering the native parse...

Vendor: rubygems
Product: rdiscount
Published: Apr 06, 2026
Source: GitHub
CVE-2026-5670 MEDIUM - 6.3

A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move_uploaded_file of the file /AssignmentSection/submission/upload.php. Performing a manipulation of the argument File results in unrestricted upload. The...

Published: Apr 06, 2026
Source: NVD
CVE-2026-34981 MEDIUM - 5.8

The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url() in app/services/file_service.py calls requests.get(url) with zero URL validation. The file extension check occurs AFTER the HTTP request is already made, and can be bypassed by ...

Vendor: pavelzbornik
Product: whisperX-FastAPI
Published: Apr 06, 2026
Source: NVD
CVE-2026-31313 MEDIUM - 5.4

An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Content field.

Vendor: feehi
Product: feehi_cms
Published: Apr 06, 2026
Source: NVD
CVE-2026-5704 MEDIUM - 5.0

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5666 MEDIUM - 5.3

A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The attack may be performed ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-34951 MEDIUM - 6.1

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains a reflected cross-site scripting vulnerability via the footerScripts parameter, which does not sanitize user-supplied input before...

Vendor: forceworkbench
Product: forceworkbench
Published: Apr 06, 2026
Source: NVD
CVE-2026-34589 MEDIUM - 5.0

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 06, 2026
Source: NVD
CVE-2026-34380 MEDIUM - 5.9

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr24.c at line 377. Th...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 06, 2026
Source: NVD
CVE-2026-34378 MEDIUM - 6.5

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before 3.4.9, a missing bounds check on the dataWindow attribute in EXR file headers allows an attacker to trigger a signed integer overflow ...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 06, 2026
Source: NVD
CVE-2026-33727 MEDIUM - 6.4

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole account uses nologin, so this is not a direct intera...

Vendor: pi-hole
Product: pi-hole
Published: Apr 06, 2026
Source: NVD
CVE-2026-31354 MEDIUM - 5.4

Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.

Vendor: feehi
Product: feehi_cms
Published: Apr 06, 2026
Source: NVD
CVE-2026-31353 MEDIUM - 5.4

An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

Vendor: feehi
Product: feehi_cms
Published: Apr 06, 2026
Source: NVD
CVE-2026-31352 MEDIUM - 5.4

An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Role Name parameter.

Vendor: feehi
Product: feehi_cms
Published: Apr 06, 2026
Source: NVD
CVE-2026-31351 MEDIUM - 4.8

An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

Vendor: feehi
Product: feehi_cms
Published: Apr 06, 2026
Source: NVD
CVE-2026-31350 MEDIUM - 5.4

An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Page Sign parameter.

Vendor: feehi
Product: feehi_cms
Published: Apr 06, 2026
Source: NVD
CVE-2025-47374 MEDIUM - 6.5

Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-5661 MEDIUM - 5.3

A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit is publicly available and might be used.

Published: Apr 06, 2026
Source: NVD