Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,261 - 7,280 of 13,554 CVEs
CVE-2026-34897 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34.

Vendor: David Lingren
Product: Media LIbrary Assistant
Published: Apr 06, 2026
Source: NVD
CVE-2026-33406 MEDIUM - 5.4

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, configuration values from the /api/config endpoint are placed directly into HTML value="" attributes without escaping in settings-advanced....

Vendor: pi-hole
Product: web
Published: Apr 06, 2026
Source: NVD
CVE-2026-33403 MEDIUM - 6.1

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, a reflected DOM-based XSS vulnerability in taillog.js allows an unauthenticated attacker to inject arbitrary HTML into the Pi-hole admin interface by...

Vendor: pi-hole
Product: web
Published: Apr 06, 2026
Source: NVD
CVE-2026-32602 MEDIUM - 4.2

Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration flow performs three sequential database operations...

Vendor: homarr-labs
Product: homarr
Published: Apr 06, 2026
Source: NVD
CVE-2026-31153 MEDIUM - 5.4

A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Published: Apr 06, 2026
Source: NVD
CVE-2026-31150 MEDIUM - 4.3

Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's dashboard resources.

Vendor: kaleris
Product: yard_management_solutions
Published: Apr 06, 2026
Source: NVD
CVE-2026-31067 MEDIUM - 6.8

A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.

Vendor: utt
Product: 520w_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31066 MEDIUM - 4.5

UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Vendor: utt
Product: 810g_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31065 MEDIUM - 4.5

UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formConfigCliForEngineerOnly function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Vendor: utt
Product: 520w_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31063 MEDIUM - 4.5

UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the formArpBindConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Vendor: utt
Product: 1200gw_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31062 MEDIUM - 4.5

UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtpServerDirConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Vendor: utt
Product: 520w_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31061 MEDIUM - 4.5

UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the ConfigAdvideo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Vendor: utt
Product: 810g_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31060 MEDIUM - 4.5

UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the formGroupConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Vendor: utt
Product: 810g_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31058 MEDIUM - 4.5

UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of the formConfigDnsFilterGlobal function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Vendor: utt
Product: 1200gw_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-31053 MEDIUM - 6.2

A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing malformed or circular LE fixup chains, relocation entries may be freed multiple times during error handling. A specially crafted LE binary can trigger heap corruption and cause the ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5660 MEDIUM - 6.3

A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The exp...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5659 MEDIUM - 6.3

A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/datrie.pyx of the component trie File Handler. The manipulation results in deserialization. The attack can be launched remotely. The exploit has been ma...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5650 MEDIUM - 5.3

A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried out remotely. The exp...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5649 MEDIUM - 6.3

A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /enrollment/admsnform.php of the component Endpoint. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5673 MEDIUM - 5.6

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a tr...

Published: Apr 06, 2026
Source: NVD