Total CVEs

125,681

Critical Severity

2,261

High Severity

7,827

Last 7 Days

1,170
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 761 - 780 of 22,086 CVEs
CVE-2026-41475 CRITICAL - 9.1

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated...

Vendor: bacnet-stack
Product: bacnet-stack
Published: Apr 24, 2026
Source: NVD
CVE-2026-41433 HIGH - 8.4

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows a local attacker controlling a Java workload to overwrite arbitrary host files when Java injection is enabled and OBI is ru...

Vendor: open-telemetry
Product: opentelemetry-ebpf-instrumentation
Published: Apr 24, 2026
Source: NVD
CVE-2026-41429 HIGH - 8.8

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruption issue in the NBNS packet handling path. When NetBIOS is enabled by calling NBNS.begin(...), the device listens on UDP ...

Vendor: espressif
Product: arduino-esp32
Published: Apr 24, 2026
Source: NVD
CVE-2026-41428 CRITICAL - 9.1

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the query string, an attacker can access any protected endpoint b...

Vendor: Budibase
Product: budibase
Published: Apr 24, 2026
Source: NVD

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation endpoints did not invoke the hook before persisting new clients. Deployments that configured clientPrivileges to restrict cl...

Vendor: better-auth
Product: better-auth, oauth-provider
Published: Apr 24, 2026
Source: NVD
CVE-2026-41426 MEDIUM - 6.1

pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by embedding malformed HTML or markdown link syntax in a user-controlled template placeholder such as the account dis...

Vendor: pretalx
Product: pretalx
Published: Apr 24, 2026
Source: NVD
CVE-2026-41425 MEDIUM - 5.4

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

Vendor: authlib
Product: authlib
Published: Apr 24, 2026
Source: NVD
CVE-2026-41244 MEDIUM - 4.7

Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), al...

Vendor: notamitgamer
Product: mojic
Published: Apr 24, 2026
Source: NVD

Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

Vendor: uuidjs
Product: uuid
Published: Apr 24, 2026
Source: NVD

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not address the root cause โ€” a redundant url.PathUnescape() call in serveExport(). An authenticated attacker can use double URL encoding (%2...

Vendor: siyuan-note
Product: siyuan
Published: Apr 24, 2026
Source: NVD
CVE-2026-41421 HIGH - 8.8

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast la...

Vendor: siyuan-note
Product: siyuan
Published: Apr 24, 2026
Source: NVD
CVE-2026-41419 HIGH - 7.6

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges to make the server ingest arbitrary host files as board attachments during BOARDS archive import. Once imported, the file can be dow...

Vendor: RARgames
Product: 4gaBoards
Published: Apr 24, 2026
Source: NVD
CVE-2026-41418 MEDIUM - 5.3

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). When an invalid username/email is provided, the server responds immediately (~17ms average). When a v...

Vendor: RARgames
Product: 4gaBoards
Published: Apr 24, 2026
Source: NVD
CVE-2026-41416 HIGH - 7.5

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead...

Vendor: pjsip
Product: pjproject
Published: Apr 24, 2026
Source: NVD
CVE-2026-41415 CRITICAL - 9.1

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerabili...

Vendor: pjsip
Product: pjproject
Published: Apr 24, 2026
Source: NVD
CVE-2026-41414 HIGH - 7.4

Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT_PRIVATE_KEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation - ...

Vendor: skim-rs
Product: skim
Published: Apr 24, 2026
Source: NVD

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations in...

Vendor: kata-containers
Product: kata-containers
Published: Apr 24, 2026
Source: NVD
CVE-2026-33666 HIGH - 7.5

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readString(), the setBitPosition() bounds check receives the overflowed value and is completely bypassed. The code then reads len bytes (512 M...

Vendor: ndsev
Product: zserio
Published: Apr 24, 2026
Source: NVD
CVE-2026-33662 HIGH - 7.5

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10, in the function emsa_pkcs1_v1_5_encode() in core/drivers/crypto/crypto_api/acipher/rsassa.c, the amount of padding nee...

Vendor: OP-TEE
Product: optee_os
Published: Apr 24, 2026
Source: NVD