Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,774
Quick preset (or use dates below)
Clear Filters
Showing 821 - 840 of 1,473 CVEs
CVE-2026-5325 LOW - 3.5

A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create Ticket. This manipulation of the argument Description causes cross site scripting. Remote exploitatio...

Published: Apr 02, 2026
Source: NVD

Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the redirect URL as a query parameter. Refresh tokens in URLs are logged in browser history, server access logs, HTTP Referer header...

Vendor: go
Product: github.com/nhost/nhost
Published: Apr 01, 2026
Source: GitHub

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

Vendor: IBM
Product: Aspera Shares
Published: Apr 01, 2026
Source: NVD

Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an authenticated NetworkManager to modify any subscriber's p...

Vendor: go
Product: github.com/ellanetworks/core
Published: Apr 01, 2026
Source: GitHub

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.

Vendor: aio-libs
Product: aiohttp
Published: Apr 01, 2026
Source: NVD
CVE-2026-2475 LOW - 3.1

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open...

Vendor: ibm
Product: security_verify_access
Published: Apr 01, 2026
Source: NVD
CVE-2026-5310 LOW - 2.5

A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptographic key . The attack must be carried out locally. This attack is characterized by high complexity. Th...

Published: Apr 01, 2026
Source: NVD

The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.

Vendor: sagedpw
Product: sage_dpw
Published: Apr 01, 2026
Source: NVD

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potent...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Apr 01, 2026
Source: NVD
CVE-2026-5254 LOW - 3.5

A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component Webhook Handler. The manipulation leads to cross site scripting. The attack may be initiated remotel...

Published: Apr 01, 2026
Source: NVD
CVE-2026-5253 LOW - 3.5

A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launch...

Published: Apr 01, 2026
Source: NVD
CVE-2026-5252 LOW - 3.5

A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been released ...

Published: Apr 01, 2026
Source: NVD
CVE-2026-5249 LOW - 3.5

A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attac...

Published: Apr 01, 2026
Source: NVD
CVE-2026-3470 LOW - 3.8

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.

Published: Mar 31, 2026
Source: NVD
CVE-2026-3469 LOW - 2.7

A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.

Published: Mar 31, 2026
Source: NVD