Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,506
Quick preset (or use dates below)
Clear Filters
Showing 7,601 - 7,620 of 13,549 CVEs
CVE-2026-28756 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter PlusĀ versions before 5802 are vulnerable toĀ Stored XSSĀ inĀ Permissions based on Distribution GroupsĀ report.

Vendor: Zohocorp
Product: ManageEngine Exchange Reporter Plus
Published: Apr 03, 2026
Source: NVD
CVE-2026-28754 HIGH - 7.3

Zohocorp ManageEngine Exchange Reporter PlusĀ versions before 5802 are vulnerable toĀ Stored XSSĀ inĀ Distribution ListsĀ report.

Vendor: Zohocorp
Product: ManageEngine Exchange Reporter Plus
Published: Apr 03, 2026
Source: NVD
CVE-2026-4350 HIGH - 8.1

The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or no...

Published: Apr 03, 2026
Source: NVD
CVE-2025-7024 HIGH - 7.3

Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable directory. This issue affects...

Published: Apr 03, 2026
Source: NVD
CVE-2026-5463 HIGH - 8.6

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended command structure and causes the Metasploit console to execute additional unintended c...

Published: Apr 03, 2026
Source: NVD
CVE-2026-35536 HIGH - 7.2

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

Vendor: tornadoweb
Product: Tornado
Published: Apr 03, 2026
Source: NVD

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects inter-Node Pod traffic. In Antrea clusters configured for dual-stack networking with IPsec encryption enabled (trafficEncryptionMode: ipsec), Antrea fails...

Vendor: go
Product: antrea.io/antrea
Published: Apr 03, 2026
Source: GitHub

Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15.

Vendor: pip
Product: ajenti-panel
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35167 HIGH - 7.1

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version strings without sanitization. Because version strings are used as path components, traversal sequence...

Vendor: pip
Product: kedro
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35037 HIGH - 7.2

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/title endpoint accepts an arbitrary URL via the website_url query parameter and makes a server-side HTTP request to it without any validation of the target host or IP address. The ...

Vendor: go
Product: github.com/lin-snow/ech0
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35036 HIGH - 7.5

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link preview (editor fetches a page title) through GET /api/website/title. That is legitimate product behavior, but the implementation is unsafe: the route is unauthenticated, accepts a...

Vendor: go
Product: github.com/lin-snow/ech0
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34986 HIGH - 7.5

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic...

Vendor: go
Product: github.com/go-jose/go-jose/v4
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35535 HIGH - 7.4

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Vendor: Sudo project
Product: Sudo
Published: Apr 03, 2026
Source: NVD
CVE-2026-28815 HIGH - 7.5

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.

Vendor: Apple
Product: macOS
Published: Apr 03, 2026
Source: NVD
CVE-2026-34780 HIGH - 8.4

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the co...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34774 HIGH - 8.1

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34771 HIGH - 7.5

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34770 HIGH - 7.0

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected,...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34769 HIGH - 7.8

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps ...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-32173 HIGH - 8.6

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: azure_sre_agent
Published: Apr 03, 2026
Source: NVD