Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,636
Quick preset (or use dates below)
Clear Filters
Showing 7,261 - 7,280 of 13,544 CVEs
CVE-2026-1343 HIGH - 7.2

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are pr...

Vendor: ibm
Product: security_verify_access
Published: Apr 08, 2026
Source: NVD
CVE-2026-5747 HIGH - 7.5

An out-of-bounds write issue in the virtio PCI transport in Amazon Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-1342 HIGH - 8.5

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from o...

Vendor: ibm
Product: security_verify_access
Published: Apr 08, 2026
Source: NVD
CVE-2026-35568 HIGH - 5.7

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or n...

Vendor: modelcontextprotocol
Product: java-sdk
Published: Apr 07, 2026
Source: NVD
CVE-2026-34079 HIGH - 7.5

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the...

Vendor: flatpak
Product: flatpak
Published: Apr 07, 2026
Source: NVD
CVE-2026-31790 HIGH - 7.5

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-28390 HIGH - 7.5

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial ...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-28389 HIGH - 7.5

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of S...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-28388 HIGH - 7.5

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. ...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-35533 HIGH - 7.7

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and ...

Vendor: jdx
Product: mise
Published: Apr 07, 2026
Source: NVD
CVE-2026-34045 HIGH - 8.2

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limi...

Vendor: podman-desktop
Product: podman-desktop
Published: Apr 07, 2026
Source: NVD
CVE-2026-29181 HIGH - 7.5

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, e...

Vendor: open-telemetry
Product: opentelemetry-go
Published: Apr 07, 2026
Source: NVD
CVE-2026-5741 HIGH - 7.3

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out...

Published: Apr 07, 2026
Source: NVD
CVE-2026-5739 HIGH - 7.3

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed r...

Vendor: maven
Product: tech.powerjob:powerjob-server-starter
Published: Apr 07, 2026
Source: NVD
CVE-2026-39376 HIGH - 7.5

FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns an HTML page containing a <meta http-equiv="refresh"> tag, it recursively calls itself with the redirect URL โ€” with no depth limit, no visited-URL deduplication, an...

Vendor: kagisearch
Product: fastfeedparser
Published: Apr 07, 2026
Source: NVD
CVE-2026-39371 HIGH - 8.1

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger stat...

Vendor: redwoodjs
Product: sdk
Published: Apr 07, 2026
Source: NVD
CVE-2026-39370 HIGH - 7.1

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm to bypass SSRF validation. The server then fetche...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD
CVE-2026-39369 HIGH - 7.6

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose server-local files through the GIF poster storage p...

Vendor: WWBN
Product: AVideo
Published: Apr 07, 2026
Source: NVD
CVE-2026-39361 HIGH - 7.7

OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichment_table/mod.rs fails to block IPv6 addresses because Rust's url crate returns them with surrounding brackets (e.g. "[::1]" not ":...

Vendor: openobserve
Product: openobserve
Published: Apr 07, 2026
Source: NVD
CVE-2026-39356 HIGH - 7.5

Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or back...

Vendor: drizzle-team
Product: drizzle-orm
Published: Apr 07, 2026
Source: NVD