Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,604
Quick preset (or use dates below)
Clear Filters
Showing 7,601 - 7,620 of 13,935 CVEs
CVE-2026-20085 MEDIUM - 6.1

A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2026-20042 MEDIUM - 6.5

A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypt...

Vendor: Cisco
Product: Cisco Nexus Dashboard
Published: Apr 01, 2026
Source: NVD
CVE-2026-20041 MEDIUM - 6.1

A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An atta...

Vendor: Cisco
Product: Cisco Nexus Dashboard, Cisco Nexus Dashboard Insights
Published: Apr 01, 2026
Source: NVD
CVE-2026-5175 MEDIUM - 5.0

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests.ย  This issue affects Server...

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4989 MEDIUM - 4.3

Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from 2026.1.1 through 202...

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4927 MEDIUM - 6.5

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4925 MEDIUM - 5.0

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from 2026.1.6 through 2026.1.1...

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-4829 MEDIUM - 5.4

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

Vendor: devolutions
Product: devolutions_server
Published: Apr 01, 2026
Source: NVD
CVE-2026-34510 MEDIUM - 5.3

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended ac...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 01, 2026
Source: NVD
CVE-2025-67807 MEDIUM - 4.7

The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behaviour in newer versions.

Vendor: sagedpw
Product: sage_dpw
Published: Apr 01, 2026
Source: NVD
CVE-2025-67805 MEDIUM - 5.9

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposing sensitive information such as hashes and table names. This feature is disabled by default in all installations and never available in Sage DPW Cloud...

Vendor: sagedpw
Product: sage_dpw
Published: Apr 01, 2026
Source: NVD
CVE-2026-30526 MEDIUM - 6.1

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login page, specifically within the msg parameter. The application reflects the content of the msg parameter back to the user without proper HTML encoding or ...

Vendor: pushpam02
Product: zoo_management_system
Published: Apr 01, 2026
Source: NVD
CVE-2026-30523 MEDIUM - 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the d...

Vendor: oretnom23
Product: loan_management_system
Published: Apr 01, 2026
Source: NVD
CVE-2026-29598 MEDIUM - 5.4

Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name and Last Name parameters.

Published: Apr 01, 2026
Source: NVD
CVE-2025-13535 MEDIUM - 6.4

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The ...

Vendor: kingaddons
Product: King Addons for Elementor โ€“ 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
Published: Apr 01, 2026
Source: NVD
CVE-2026-3877 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered ...

Vendor: vertigis
Product: fm
Published: Apr 01, 2026
Source: NVD
CVE-2026-34999 MEDIUM - 5.3

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can...

Vendor: Volcengine
Product: OpenViking
Published: Apr 01, 2026
Source: NVD
CVE-2026-30522 MEDIUM - 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific penalty rates for overdue payments. While the frontend interface prevents users from enteri...

Vendor: oretnom23
Product: loan_management_system
Published: Apr 01, 2026
Source: NVD
CVE-2026-25601 MEDIUM - 6.4

A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords...

Vendor: Metronik d.o.o.
Product: MEPIS RM
Published: Apr 01, 2026
Source: NVD
CVE-2026-1879 MEDIUM - 6.3

A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the attac...

Published: Apr 01, 2026
Source: NVD