Total CVEs

125,843

Critical Severity

2,274

High Severity

7,870

Last 7 Days

1,173
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 61 - 80 of 7,570 CVEs
CVE-2026-42234 HIGH - 7.5

n8n has a Python Task Runner Sandbox Escape Vulnerability

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub

n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7404 HIGH - 7.3

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It is possible to initiat...

Published: Apr 29, 2026
Source: NVD
CVE-2025-50328 HIGH - 7.3

A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and extracted using B1 Free Archiver, the software fails to propagate the 'Zone.Identifier' alte...

Published: Apr 29, 2026
Source: NVD
CVE-2026-42224 HIGH - 7.7

ipl/web is vulnerable to reflected XSS by malformed search requests

Vendor: composer
Product: ipl/web
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41643 HIGH - 7.5

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41642 HIGH - 7.5

GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub

CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40902 HIGH - 7.5

PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40863 HIGH - 7.5

PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub

PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7426 HIGH - 8.1

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7400 HIGH - 7.3

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit has...

Published: Apr 29, 2026
Source: NVD
CVE-2026-34965 HIGH - 8.8

Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP c...

Vendor: Cockpit
Product: Cockpit CMS
Published: Apr 29, 2026
Source: NVD
CVE-2018-25315 HIGH - 8.4

Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with structured exception handler (SEH) overwrite and shellcode to achieve code exec...

Vendor: Alloksoft
Product: Video Joiner
Published: Apr 29, 2026
Source: NVD
CVE-2018-25314 HIGH - 8.4

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handle...

Vendor: Alloksoft
Product: WMV to AVI MPEG DVD WMV Converter
Published: Apr 29, 2026
Source: NVD
CVE-2018-25309 HIGH - 7.2

MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers o...

Vendor: mybb
Product: MyBB Recent threads
Published: Apr 29, 2026
Source: NVD
CVE-2018-25308 HIGH - 8.8

BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink f...

Vendor: donmik
Product: Buddypress Xprofile Custom Fields Type
Published: Apr 29, 2026
Source: NVD
CVE-2018-25307 HIGH - 8.4

SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key. Attackers can inject shellcode through the Unlock Key field during registration to execute arbitrar...

Vendor: Sysgauge
Product: SysGauge Pro
Published: Apr 29, 2026
Source: NVD
CVE-2018-25304 HIGH - 8.4

Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > ...

Vendor: Filehippo
Product: Free Download Manager
Published: Apr 29, 2026
Source: NVD