Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,607
Quick preset (or use dates below)
Clear Filters
Showing 7,581 - 7,600 of 13,935 CVEs
CVE-2026-5311 MEDIUM - 5.3

A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function Webdav_Acc...

Vendor: dlink
Product: dnr-202l_firmware
Published: Apr 01, 2026
Source: NVD
CVE-2026-34750 MEDIUM - 6.5

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3, the client-upload signed-URL endpoints for S3, GCS, Azure, and R2 did not properly sanitize filenam...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD
CVE-2026-34749 MEDIUM - 5.4

Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made. Thi...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD
CVE-2025-66442 MEDIUM - 5.1

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-35000 MEDIUM - 6.5

ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked XPath 3.0/3.1 functions such as json-doc() and similar file-access primitives. Attackers can exploit the...

Vendor: dgtlmoon
Product: ChangeDetection.io
Published: Apr 01, 2026
Source: NVD
CVE-2026-34871 MEDIUM - 6.7

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-34447 MEDIUM - 5.5

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue has been patched in version 1.21.0.

Vendor: onnx
Product: onnx
Published: Apr 01, 2026
Source: NVD
CVE-2026-34446 MEDIUM - 4.7

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path traversal, but completely misses hardlinks because a hardlink looks exactly like a regular file on the ...

Vendor: onnx
Product: onnx
Published: Apr 01, 2026
Source: NVD
CVE-2026-34397 MEDIUM - 6.3

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose mapp...

Vendor: himmelblau-idm
Product: himmelblau
Published: Apr 01, 2026
Source: NVD
CVE-2026-25834 MEDIUM - 6.5

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-33978 MEDIUM - 5.4

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mo...

Vendor: streetwriters
Product: notesnook
Published: Apr 01, 2026
Source: NVD
CVE-2026-2265 MEDIUM - 6.5

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.

Published: Apr 01, 2026
Source: NVD
CVE-2026-20174 MEDIUM - 4.9

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerabi...

Vendor: Cisco
Product: Cisco Nexus Dashboard, Cisco Nexus Dashboard Insights
Published: Apr 01, 2026
Source: NVD
CVE-2026-20097 MEDIUM - 6.5

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interf...

Vendor: Cisco
Product: Cisco Unified Computing System (Standalone)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20096 MEDIUM - 6.5

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper v...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20095 MEDIUM - 6.5

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper v...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20090 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20089 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20088 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20087 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD