Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,507
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,621 - 7,640 of 13,564 CVEs
CVE-2025-67805 MEDIUM - 5.9

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposing sensitive information such as hashes and table names. This feature is disabled by default in all installations and never available in Sage DPW Cloud...

Vendor: sagedpw
Product: sage_dpw
Published: Apr 01, 2026
Source: NVD
CVE-2026-30526 MEDIUM - 6.1

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login page, specifically within the msg parameter. The application reflects the content of the msg parameter back to the user without proper HTML encoding or ...

Vendor: pushpam02
Product: zoo_management_system
Published: Apr 01, 2026
Source: NVD
CVE-2026-30523 MEDIUM - 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the d...

Vendor: oretnom23
Product: loan_management_system
Published: Apr 01, 2026
Source: NVD
CVE-2026-29598 MEDIUM - 5.4

Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name and Last Name parameters.

Published: Apr 01, 2026
Source: NVD
CVE-2025-13535 MEDIUM - 6.4

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The ...

Vendor: kingaddons
Product: King Addons for Elementor โ€“ 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
Published: Apr 01, 2026
Source: NVD
CVE-2026-3877 MEDIUM - 6.1

A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered ...

Vendor: vertigis
Product: fm
Published: Apr 01, 2026
Source: NVD
CVE-2026-34999 MEDIUM - 5.3

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can...

Vendor: Volcengine
Product: OpenViking
Published: Apr 01, 2026
Source: NVD
CVE-2026-30522 MEDIUM - 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific penalty rates for overdue payments. While the frontend interface prevents users from enteri...

Vendor: oretnom23
Product: loan_management_system
Published: Apr 01, 2026
Source: NVD
CVE-2026-25601 MEDIUM - 6.4

A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords...

Vendor: Metronik d.o.o.
Product: MEPIS RM
Published: Apr 01, 2026
Source: NVD
CVE-2026-1879 MEDIUM - 6.3

A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the attac...

Published: Apr 01, 2026
Source: NVD
CVE-2024-53828 MEDIUM - 5.3

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Apr 01, 2026
Source: NVD
CVE-2026-34889 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows DOM-Based XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a before 3.21.4.

Vendor: Brainstorm Force
Product: Ultimate Addons for WPBakery Page Builder
Published: Apr 01, 2026
Source: NVD
CVE-2026-5259 MEDIUM - 6.3

A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/controller/AlarmController.java of the component Alarm Preview. Executing a manipulation can lead to server...

Published: Apr 01, 2026
Source: NVD
CVE-2026-28265 MEDIUM - 4.4

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

Vendor: Dell
Product: PowerStore, PowerStore 500T, PowerStore 1000T, PowerStore 1200T, PowerStore 3000T, PowerStore 3200Q, PowerStore 3200T, PowerStore 5000T, PowerStore 5200Q, PowerStore 5200T, PowerStore 7000T, PowerStore 9000T, PowerStore 9200T
Published: Apr 01, 2026
Source: NVD
CVE-2026-27101 MEDIUM - 4.7

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker within the management network could potentially exploi...

Vendor: Dell
Product: Secure Connect Gateway
Published: Apr 01, 2026
Source: NVD
CVE-2026-5255 MEDIUM - 4.3

A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in cross site scripting. The attack may be launched remotely. The exploit is now pub...

Vendor: code-projects
Product: simple_laundry_system
Published: Apr 01, 2026
Source: NVD
CVE-2026-2696 MEDIUM - 5.3

The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern using a random 6-digit number. These files are stored in the publicly accessible wp-content/uploads/ directory. As a result, any unauthenticated user can b...

Published: Apr 01, 2026
Source: NVD
CVE-2026-5291 MEDIUM - 4.3

Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: Apr 01, 2026
Source: NVD
CVE-2026-5287 MEDIUM - 6.3

Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 01, 2026
Source: NVD
CVE-2026-5285 MEDIUM - 6.3

Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 01, 2026
Source: NVD