Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
Showing 7,441 - 7,460 of 13,935 CVEs
CVE-2026-35539 MEDIUM - 6.1

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

Vendor: Roundcube
Product: Webmail
Published: Apr 03, 2026
Source: NVD

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the ser...

Vendor: pip
Product: dtale
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34779 MEDIUM - 6.5

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the appli...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34778 MEDIUM - 5.9

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and relat...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34777 MEDIUM - 5.4

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionR...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34776 MEDIUM - 5.3

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted second...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34775 MEDIUM - 6.8

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawne...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34773 MEDIUM - 4.7

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrust...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34772 MEDIUM - 5.8

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow downloads and programmatically destroy sessions may be vulnerable to a use-after-free. If a session is torn down while ...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34767 MEDIUM - 5.9

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via webR...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35508 MEDIUM - 5.4

Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,

Vendor: milesmcc
Product: Shynet
Published: Apr 03, 2026
Source: NVD
CVE-2026-35507 MEDIUM - 6.4

Shynet before 0.14.0 allows Host header injection in the password reset flow.

Vendor: milesmcc
Product: Shynet
Published: Apr 03, 2026
Source: NVD
CVE-2026-35466 MEDIUM - 6.1

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

Vendor: CERT/CC
Product: cveClient/cveInterface.js
Published: Apr 02, 2026
Source: NVD
CVE-2026-30252 MEDIUM - 6.1

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url paramete...

Published: Apr 02, 2026
Source: NVD
CVE-2026-30251 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.

Vendor: interzen
Product: zenshare_suite
Published: Apr 02, 2026
Source: NVD
CVE-2026-35383 MEDIUM - 6.5

Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to enumerate or delete assets...

Vendor: Bentley Systems
Product: iTwin Platform
Published: Apr 02, 2026
Source: NVD
CVE-2026-34848 MEDIUM - 5.4

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version 2026.3.0.

Vendor: hoppscotch
Product: hoppscotch
Published: Apr 02, 2026
Source: NVD
CVE-2026-34847 MEDIUM - 4.7

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and redirect the user without proper validation. This issue has been patched in versio...

Vendor: hoppscotch
Product: hoppscotch
Published: Apr 02, 2026
Source: NVD
CVE-2026-34832 MEDIUM - 6.5

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/dele...

Vendor: Erudika
Product: scoold
Published: Apr 02, 2026
Source: NVD
CVE-2026-34760 MEDIUM - 5.9

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 specifies a weighted downmixing algorithm. This discrepancy resul...

Vendor: vllm-project
Product: vllm
Published: Apr 02, 2026
Source: NVD