Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,208
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 721 - 740 of 22,583 CVEs
CVE-2026-35579 HIGH - 7.5

CoreDNS has TSIG authentication bypass on gRPC and QUIC transports

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub

PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 28, 2026
Source: GitHub
CVE-2026-33190 HIGH - 7.5

CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-33489 HIGH - 7.5

CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-32936 HIGH - 7.5

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-32934 HIGH - 7.5

CoreDNS' DoQ worker pool does not bound stream backlog

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-32699 MEDIUM - 4.3

FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field

Vendor: composer
Product: facturascripts/facturascripts
Published: Apr 28, 2026
Source: GitHub
CVE-2026-30246 MEDIUM - 6.5

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

Vendor: go
Product: github.com/gofiber/fiber/v3
Published: Apr 28, 2026
Source: GitHub
CVE-2026-7319 HIGH - 7.3

A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_system_mcp/server.py of the component add_action Tool. This manipulation of the argument context causes path traversal. The attack can be initiated remot...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7318 MEDIUM - 5.9

A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path traversal. Attacking locally is a requirement. The exploit is now public and may be used. The project was ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7317 MEDIUM - 5.0

A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be la...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7316 HIGH - 7.3

A vulnerability has been found in eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af. Affected is an unknown function of the file aider_mcp.py of the component code_with_ai. The manipulation of the argument working_dir/editable_files leads to command injection. The attack may be ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7315 HIGH - 7.3

A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The explo...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7314 HIGH - 7.3

A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public an...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7306 MEDIUM - 5.6

A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_token...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7305 MEDIUM - 6.3

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server-...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7303 LOW - 3.7

A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improper ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7297 LOW - 2.4

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The expl...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7296 LOW - 2.4

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack is possible. The explo...

Published: Apr 28, 2026
Source: NVD
CVE-2026-41649 HIGH - 7.7

Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId` and `documentId` are provided in the request, the authorization logic only check...

Vendor: outline
Product: outline
Published: Apr 28, 2026
Source: NVD