Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,638
Quick preset (or use dates below)
Clear Filters
Showing 7,421 - 7,440 of 13,935 CVEs
CVE-2026-5475 MEDIUM - 5.5

A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The project was informed of the problem early through an issue report but...

Published: Apr 03, 2026
Source: NVD
CVE-2026-32186 MEDIUM - 6.5

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

Published: Apr 03, 2026
Source: NVD
CVE-2026-5474 MEDIUM - 6.3

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must have access to the lo...

Published: Apr 03, 2026
Source: NVD
CVE-2026-5473 MEDIUM - 4.5

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The exploitability is regarde...

Published: Apr 03, 2026
Source: NVD
CVE-2026-5472 MEDIUM - 6.3

A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php of the component Profile Picture Handler. This manipulation of the argument File causes unrestricted...

Published: Apr 03, 2026
Source: NVD
CVE-2026-5470 MEDIUM - 6.3

A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractContent of the file src/services/content-extractor.service.ts of the component Model Context Protocol ...

Published: Apr 03, 2026
Source: NVD
CVE-2026-25043 MEDIUM - 5.3

Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the “Forgot Password” endpoint. An unauthenticated attacker can rep...

Vendor: Budibase
Product: budibase
Published: Apr 03, 2026
Source: NVD

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible that a compromised workload machine under a Juju co...

Vendor: juju
Product: juju
Published: Apr 03, 2026
Source: NVD
CVE-2026-34756 MEDIUM - 6.5

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the n parameter in the ChatCompletionRequest and CompletionRequest...

Vendor: pip
Product: vllm
Published: Apr 03, 2026
Source: GitHub
CVE-2026-5469 MEDIUM - 4.7

A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not res...

Vendor: casbin
Product: casdoor
Published: Apr 03, 2026
Source: NVD
CVE-2025-59709 MEDIUM - 6.8

An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.

Vendor: kovai
Product: biztalk360
Published: Apr 03, 2026
Source: NVD
CVE-2026-28736 MEDIUM - 4.3

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. This allows an authenticated attacker who knows a victim's fileID to read the content of the file. NOTE: Focalboard as a standalone product is not maintained and no fix will be i...

Vendor: Mattermost
Product: Focalboard
Published: Apr 03, 2026
Source: NVD
CVE-2026-5467 MEDIUM - 4.3

A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The exploit is publicly a...

Vendor: casbin
Product: casdoor
Published: Apr 03, 2026
Source: NVD
CVE-2026-35549 MEDIUM - 6.5

An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses all...

Vendor: MariaDB
Product: MariaDB
Published: Apr 03, 2026
Source: NVD
CVE-2026-35545 MEDIUM - 5.3

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

Vendor: Roundcube
Product: Webmail
Published: Apr 03, 2026
Source: NVD
CVE-2026-35544 MEDIUM - 5.3

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

Vendor: Roundcube
Product: Webmail
Published: Apr 03, 2026
Source: NVD
CVE-2026-35543 MEDIUM - 5.3

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

Vendor: Roundcube
Product: Webmail
Published: Apr 03, 2026
Source: NVD
CVE-2026-35542 MEDIUM - 5.3

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

Vendor: Roundcube
Product: Webmail
Published: Apr 03, 2026
Source: NVD
CVE-2026-35541 MEDIUM - 4.2

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

Vendor: Roundcube
Product: Webmail
Published: Apr 03, 2026
Source: NVD
CVE-2026-35540 MEDIUM - 5.4

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

Vendor: Roundcube
Product: Webmail
Published: Apr 03, 2026
Source: NVD