Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
Showing 7,461 - 7,480 of 13,935 CVEs
CVE-2026-5417 MEDIUM - 4.7

A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. This manipulation of the argument address causes server-side request forgery. The attack may be initiate...

Published: Apr 02, 2026
Source: NVD
CVE-2026-34736 MEDIUM - 5.3

Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthenticated attacker can fully bypass the email verification process by combining two issues: the OAuth2 password grant issuing tokens to inactive users (do...

Vendor: openedx
Product: openedx-platform
Published: Apr 02, 2026
Source: NVD
CVE-2026-34425 MEDIUM - 5.4

OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execu...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 02, 2026
Source: NVD
CVE-2025-43238 MEDIUM - 6.2

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43210 MEDIUM - 6.3

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted media file may lead to une...

Vendor: Apple
Product: iOS and iPadOS, iPadOS, macOS, tvOS, visionOS, watchOS
Published: Apr 02, 2026
Source: NVD
CVE-2026-5414 MEDIUM - 5.3

A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The manipulation of the argument DocumentId results in improper control of resource identifiers. The attack may be performed from...

Published: Apr 02, 2026
Source: NVD
CVE-2026-35414 MEDIUM - 4.2

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

Vendor: OpenBSD
Product: OpenSSH
Published: Apr 02, 2026
Source: NVD
CVE-2026-34835 MEDIUM - 4.8

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host ...

Vendor: rack
Product: rack
Published: Apr 02, 2026
Source: NVD
CVE-2026-34610 MEDIUM - 5.9

The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms. Prior to version 1.7.1, lc_x509_extract_name_segment() casts size_t vlen to uint8_t when storing the Common Name (CN) length. An attacker who crafts a certificate with CN = victim...

Vendor: smuellerDD
Product: leancrypto
Published: Apr 02, 2026
Source: NVD
CVE-2026-34608 MEDIUM - 4.9

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by parsing the message body with cJSON_Parse(body). The body is obtained from nng_msg_body(msg), which is a binary buf...

Vendor: nanomq
Product: nanomq
Published: Apr 02, 2026
Source: NVD
CVE-2026-34606 MEDIUM - 6.1

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0.

Vendor: frappe
Product: lms
Published: Apr 02, 2026
Source: NVD
CVE-2026-34590 MEDIUM - 5.4

Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which validates the url field with only @IsUrl() (format check), missing the @IsSafeWebhookUrl validator that blocks internal/private network addresses. The upda...

Vendor: gitroomhq
Product: postiz-app
Published: Apr 02, 2026
Source: NVD
CVE-2026-34584 MEDIUM - 5.4

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to access to lists (which they don't have access to) under different scenarios. This only affects multi...

Vendor: knadh
Product: listmonk
Published: Apr 02, 2026
Source: NVD
CVE-2026-34124 MEDIUM - 6.5

A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent networ...

Vendor: TP-Link Systems Inc.
Product: Tapo C520WS v2.6
Published: Apr 02, 2026
Source: NVD
CVE-2026-34122 MEDIUM - 6.5

A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling component due to insufficient input validation. An attacker can exploit this vulnerability by supplying an excessively long value for a vulnerable configuration parameter, resultin...

Vendor: TP-Link Systems Inc.
Product: Tapo C520WS v2.6
Published: Apr 02, 2026
Source: NVD
CVE-2026-34120 MEDIUM - 6.5

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of local video stream content due to insufficient alignment and validation of buffer boundaries when processing streaming inputs.An attacker on the same network segment could trigger...

Vendor: TP-Link Systems Inc.
Product: Tapo C520WS v2.6
Published: Apr 02, 2026
Source: NVD
CVE-2026-34119 MEDIUM - 6.5

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request bodies without continuous write‑boundary verification, due to insufficient boundary validation when handling externally supplied HTTP input.  An attacke...

Vendor: TP-Link Systems Inc.
Product: Tapo C520WS v2.6
Published: Apr 02, 2026
Source: NVD
CVE-2026-34118 MEDIUM - 6.5

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input.  An attacke...

Vendor: TP-Link Systems Inc.
Product: Tapo C520WS v2.6
Published: Apr 02, 2026
Source: NVD
CVE-2026-33271 MEDIUM - 6.7

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902.

Vendor: Acronis
Product: Acronis True Image
Published: Apr 02, 2026
Source: NVD
CVE-2026-32762 MEDIUM - 4.8

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling quoted-string values. Because quoted values may legally contain semicolons, ...

Vendor: rack
Product: rack
Published: Apr 02, 2026
Source: NVD