Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,507
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,601 - 7,620 of 13,564 CVEs
CVE-2026-33978 MEDIUM - 5.4

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mo...

Vendor: streetwriters
Product: notesnook
Published: Apr 01, 2026
Source: NVD
CVE-2026-2265 MEDIUM - 6.5

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.

Published: Apr 01, 2026
Source: NVD
CVE-2026-20174 MEDIUM - 4.9

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerabi...

Vendor: Cisco
Product: Cisco Nexus Dashboard, Cisco Nexus Dashboard Insights
Published: Apr 01, 2026
Source: NVD
CVE-2026-20097 MEDIUM - 6.5

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interf...

Vendor: Cisco
Product: Cisco Unified Computing System (Standalone)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20096 MEDIUM - 6.5

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper v...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20095 MEDIUM - 6.5

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper v...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20090 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20089 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20088 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20087 MEDIUM - 4.8

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exp...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20085 MEDIUM - 6.1

A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20042 MEDIUM - 6.5

A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypt...

Vendor: Cisco
Product: Cisco Nexus Dashboard
Published: Apr 01, 2026
Source: NVD
CVE-2026-20041 MEDIUM - 6.1

A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An atta...

Vendor: Cisco
Product: Cisco Nexus Dashboard, Cisco Nexus Dashboard Insights
Published: Apr 01, 2026
Source: NVD
CVE-2026-5175 MEDIUM - 5.0

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests.ย  This issue affects Server...

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4989 MEDIUM - 4.3

Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from 2026.1.1 through 202...

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4927 MEDIUM - 6.5

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4925 MEDIUM - 5.0

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from 2026.1.6 through 2026.1.1...

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4829 MEDIUM - 5.4

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-34510 MEDIUM - 5.3

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended ac...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 01, 2026
Source: NVD
CVE-2025-67807 MEDIUM - 4.7

The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behaviour in newer versions.

Vendor: sagedpw
Product: sage_dpw
Published: Apr 01, 2026
Source: NVD