Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,527
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,581 - 7,600 of 13,564 CVEs
CVE-2026-4820 MEDIUM - 4.3

IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the i...

Vendor: ibm
Product: maximo_application_suite
Published: Apr 01, 2026
Source: NVD
CVE-2026-4364 MEDIUM - 5.4

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows certificate listings retrieved via a browser session to return a JSON...

Vendor: ibm
Product: security_verify_access
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD
CVE-2026-34516 MEDIUM - 7.5

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD
CVE-2026-2862 MEDIUM - 5.3

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive inform...

Vendor: ibm
Product: security_verify_access
Published: Apr 01, 2026
Source: NVD
CVE-2026-22815 MEDIUM - 7.5

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD
CVE-2026-1491 MEDIUM - 5.3

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive inform...

Vendor: ibm
Product: security_verify_access
Published: Apr 01, 2026
Source: NVD
CVE-2025-36373 MEDIUM - 4.1

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.

Vendor: IBM
Product: DataPower Gateway 10.6CD, DataPower Gateway 10.5.0, DataPower Gateway 10.6.0
Published: Apr 01, 2026
Source: NVD
CVE-2025-13916 MEDIUM - 5.9

IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

Vendor: IBM
Product: Aspera Shares
Published: Apr 01, 2026
Source: NVD
CVE-2026-5311 MEDIUM - 5.3

A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function Webdav_Acc...

Vendor: dlink
Product: dnr-202l_firmware
Published: Apr 01, 2026
Source: NVD
CVE-2026-34750 MEDIUM - 6.5

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3, the client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenam...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD
CVE-2026-34749 MEDIUM - 5.4

Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made. Thi...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD
CVE-2025-66442 MEDIUM - 5.1

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-35000 MEDIUM - 6.5

ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. Attackers can exploit the...

Vendor: dgtlmoon
Product: ChangeDetection.io
Published: Apr 01, 2026
Source: NVD
CVE-2026-34871 MEDIUM - 6.7

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-34447 MEDIUM - 5.5

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue has been patched in version 1.21.0.

Vendor: onnx
Product: onnx
Published: Apr 01, 2026
Source: NVD
CVE-2026-34446 MEDIUM - 4.7

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path traversal, but completely misses hardlinks because a hardlink looks exactly like a regular file on the ...

Vendor: onnx
Product: onnx
Published: Apr 01, 2026
Source: NVD
CVE-2026-34397 MEDIUM - 6.3

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose mapp...

Vendor: himmelblau-idm
Product: himmelblau
Published: Apr 01, 2026
Source: NVD
CVE-2026-25834 MEDIUM - 6.5

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD