Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,507
Quick preset (or use dates below)
Clear Filters
Showing 7,581 - 7,600 of 13,549 CVEs
CVE-2026-22664 HIGH - 7.7

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validati...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD
CVE-2026-22663 HIGH - 7.5

prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized users to access sensitive data associated with private prompts. Attackers can exploit these missing au...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD
CVE-2026-22661 HIGH - 8.1

prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archives with unsanitized filenames containing path traversal sequences. Attackers can exploit missing ser...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD
CVE-2025-10681 HIGH - 8.6

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers.

Vendor: Gardyn
Product: Mobile Application, Cloud API
Published: Apr 03, 2026
Source: NVD
CVE-2022-4987 HIGH - 7.3

Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of user-configured external applications that allows a local attacker to execute arbitrary binaries. Due to insufficient path sanitization, an attacker can place a malicious binary i...

Published: Apr 03, 2026
Source: NVD
CVE-2020-37216 HIGH - 7.5

Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a l...

Vendor: Belden
Product: Hirschmann HiOS
Published: Apr 03, 2026
Source: NVD
CVE-2026-35218 HIGH - 8.7

Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, queries, automations) using Svelte's {@html} directive without any sanitization. An authenticated user with Builder access can create a table, auto...

Vendor: Budibase
Product: budibase
Published: Apr 03, 2026
Source: NVD
CVE-2026-35214 HIGH - 8.7

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker with Global Builder privileges can craft a multip...

Vendor: Budibase
Product: budibase
Published: Apr 03, 2026
Source: NVD
CVE-2026-25044 HIGH - 8.8

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows template interpolation, potentially allowing arbitr...

Vendor: Budibase
Product: budibase
Published: Apr 03, 2026
Source: NVD

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ā€˜charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju control...

Vendor: juju
Product: juju
Published: Apr 03, 2026
Source: NVD
CVE-2026-26477 HIGH - 7.5

An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file

Vendor: dokuwiki
Product: dokuwiki
Published: Apr 03, 2026
Source: NVD
CVE-2025-59711 HIGH - 8.3

An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal.

Vendor: kovai
Product: biztalk360
Published: Apr 03, 2026
Source: NVD
CVE-2025-59710 HIGH - 8.8

An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the serve...

Vendor: kovai
Product: biztalk360
Published: Apr 03, 2026
Source: NVD
CVE-2026-25773 HIGH - 8.1

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reordering categories. An attacker can inject a malicious SQL payload into the category id field, which is stored in the database and later executed unsani...

Vendor: Mattermost
Product: Focalboard
Published: Apr 03, 2026
Source: NVD
CVE-2026-27655 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS inĀ Permissions Based on MailboxesĀ report.

Vendor: Zohocorp
Product: ManageEngine Exchange Reporter Plus
Published: Apr 03, 2026
Source: NVD
CVE-2026-4108 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS inĀ Non-Owner MailboxĀ PermissionĀ report.

Vendor: zohocorp
Product: manageengine_exchange_reporter_plus
Published: Apr 03, 2026
Source: NVD
CVE-2026-4107 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS inĀ Folder Message Count and SizeĀ report.

Vendor: zohocorp
Product: manageengine_exchange_reporter_plus
Published: Apr 03, 2026
Source: NVD
CVE-2026-3880 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS inĀ Public Folder Client PermissionsĀ report.

Vendor: zohocorp
Product: manageengine_exchange_reporter_plus
Published: Apr 03, 2026
Source: NVD
CVE-2026-3879 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS inĀ Equipment Mailbox DetailsĀ report.

Vendor: zohocorp
Product: manageengine_exchange_reporter_plus
Published: Apr 03, 2026
Source: NVD
CVE-2026-28703 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter PlusĀ versions before 5802 are vulnerable toĀ Stored XSSĀ inĀ Mails Exchanged Between UsersĀ report.

Vendor: Zohocorp
Product: ManageEngine Exchange Reporter Plus
Published: Apr 03, 2026
Source: NVD