Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,519
Quick preset (or use dates below)
Clear Filters
Showing 7,741 - 7,760 of 13,935 CVEs
CVE-2026-24029 MEDIUM - 6.5

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.

Vendor: PowerDNS
Product: DNSdist
Published: Mar 31, 2026
Source: NVD
CVE-2026-24028 MEDIUM - 5.3

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential info...

Vendor: PowerDNS
Product: DNSdist
Published: Mar 31, 2026
Source: NVD
CVE-2026-34887 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0.

Vendor: Extend Themes
Product: Kubio AI Page Builder
Published: Mar 31, 2026
Source: NVD
CVE-2026-5197 MEDIUM - 6.3

A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

Published: Mar 31, 2026
Source: NVD
CVE-2026-5196 MEDIUM - 6.3

A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be use...

Published: Mar 31, 2026
Source: NVD
CVE-2026-3107 MEDIUM - 5.4

Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, al...

Vendor: teampass
Product: teampass
Published: Mar 31, 2026
Source: NVD
CVE-2026-3106 MEDIUM - 5.4

Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode...

Vendor: teampass
Product: teampass
Published: Mar 31, 2026
Source: NVD
CVE-2025-41357 MEDIUM - 6.1

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies,...

Vendor: Anon Proxy Server
Product: Anon Proxy Server
Published: Mar 31, 2026
Source: NVD
CVE-2025-41356 MEDIUM - 6.1

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies,...

Vendor: Anon Proxy Server
Product: Anon Proxy Server
Published: Mar 31, 2026
Source: NVD
CVE-2025-41355 MEDIUM - 6.1

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cook...

Vendor: Anon Proxy Server
Product: Anon Proxy Server
Published: Mar 31, 2026
Source: NVD
CVE-2026-5186 MEDIUM - 5.3

A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. This manipulation causes double free. The attack requires local access. The exploit has been made available to the public an...

Published: Mar 31, 2026
Source: NVD
CVE-2026-5185 MEDIUM - 5.3

A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has bee...

Published: Mar 31, 2026
Source: NVD
CVE-2026-5184 MEDIUM - 6.3

A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file /goform/setSysAdm. The manipulation of the argument admuser leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. ...

Published: Mar 31, 2026
Source: NVD
CVE-2026-3881 MEDIUM - 5.8

The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks

Published: Mar 31, 2026
Source: NVD
CVE-2026-5183 MEDIUM - 6.3

A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the file /goform/addRouting. Executing a manipulation of the argument dest can lead to command injection. It is possible to launch the attack remotely. The exploit has been publicly di...

Published: Mar 31, 2026
Source: NVD
CVE-2026-34881 MEDIUM - 5.0

OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the...

Vendor: OpenStack
Product: Glance
Published: Mar 31, 2026
Source: NVD
CVE-2026-1877 MEDIUM - 6.1

The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.84. This is due to missing nonce validation on the 'aps_options_page' function. This makes it possible for unauthenticated attackers to update settings and injec...

Published: Mar 31, 2026
Source: NVD
CVE-2026-1834 MEDIUM - 6.4

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

Published: Mar 31, 2026
Source: NVD
CVE-2026-5181 MEDIUM - 6.3

A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_category. Such manipulation of the argument img leads to unrestricted upload. The attack may be perform...

Published: Mar 31, 2026
Source: NVD
CVE-2026-4146 MEDIUM - 6.1

The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Published: Mar 31, 2026
Source: NVD