Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,527
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 7,561 - 7,580 of 13,564 CVEs
CVE-2026-34974 MEDIUM - 5.4

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSanitizer.php) can be bypassed using HTML entity encoding in javascript: URLs within SVG <a href> attributes. Any user with edit_faq permission can upload a malicious SVG that ...

Vendor: composer
Product: thorsten/phpmyfaq
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34973 MEDIUM - 5.3

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/phpMyFAQ/Search.php uses real_escape_string() (via escape()) to sanitize the search term before embedding it in LIKE clauses. However, real_escape_string() does not escape SQL LIKE ...

Vendor: composer
Product: thorsten/phpmyfaq
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34939 MEDIUM - 6.5

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python...

Vendor: pip
Product: praisonai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-5314 MEDIUM - 4.3

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made pu...

Published: Apr 01, 2026
Source: NVD
CVE-2025-66486 MEDIUM - 4.8

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

Vendor: IBM
Product: Aspera Shares
Published: Apr 01, 2026
Source: NVD
CVE-2025-66485 MEDIUM - 5.4

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. Β This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

Vendor: IBM
Product: Aspera Shares
Published: Apr 01, 2026
Source: NVD
CVE-2025-66484 MEDIUM - 5.5

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Vendor: IBM
Product: Aspera Shares
Published: Apr 01, 2026
Source: NVD
CVE-2025-66483 MEDIUM - 6.3

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

Vendor: IBM
Product: Aspera Shares
Published: Apr 01, 2026
Source: NVD
CVE-2025-36375 MEDIUM - 6.5

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut...

Vendor: IBM
Product: DataPower Gateway 10.6CD, DataPower Gateway 10.5.0, DataPower Gateway 10.6.0
Published: Apr 01, 2026
Source: NVD
CVE-2026-34761 MEDIUM - 5.8

Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB to send NGAP handover failure messages to Ella Core can crash the process, causing service disruption for all connected s...

Vendor: go
Product: github.com/ellanetworks/core
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34730 MEDIUM - 5.5

Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local...

Vendor: pip
Product: copier
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34729 MEDIUM - 6.1

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue has been patched in version 4.1.1.

Vendor: composer
Product: phpmyfaq/phpmyfaq
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34726 MEDIUM - 4.4

Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when sel...

Vendor: pip
Product: copier
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34715 MEDIUM - 5.3

ewe is a Gleam web server. Prior to version 3.0.6, the encode_headers function in src/ewe/internal/encoder.gleam directly interpolates response header keys and values into raw HTTP bytes without validating or stripping CRLF (\r\n) sequences. An application that passes user-controlled data into respo...

Vendor: erlang
Product: ewe
Published: Apr 01, 2026
Source: GitHub
CVE-2026-5313 MEDIUM - 4.3

A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and ...

Published: Apr 01, 2026
Source: NVD
CVE-2026-34562 MEDIUM - 4.7

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrati...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34561 MEDIUM - 4.7

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within System Settings – Social Media Management. Multiple configu...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34526 MEDIUM - 5.0

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, in src/endpoints/search.js, the hostname is checked against /^\d+\.\d+\.\d+\.\d+$/. This onl...

Vendor: npm
Product: sillytavern
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34523 MEDIUM - 5.3

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in the static file route handler allows any unauthenticated u...

Vendor: npm
Product: sillytavern
Published: Apr 01, 2026
Source: GitHub
CVE-2026-5312 MEDIUM - 5.3

A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the fu...

Vendor: dlink
Product: dns-1550-04_firmware
Published: Apr 01, 2026
Source: NVD