Total CVEs

125,728

Critical Severity

2,261

High Severity

7,831

Last 7 Days

1,204
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,001 - 1,020 of 22,133 CVEs
CVE-2026-31535 MEDIUM - 4.7

In the Linux kernel, the following vulnerability has been resolved: smb: client: make use of smbdirect_socket.recv_io.credits.available The logic off managing recv credits by counting posted recv_io and granted credits is racy. That's because the peer might already consumed a credit, but bet...

Vendor: Linux
Product: Linux
Published: Apr 24, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: smb: client: let send_done handle a completion without IB_SEND_SIGNALED With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in the final request that has IB_SEND_SIGNALED ...

Vendor: Linux
Product: Linux
Published: Apr 24, 2026
Source: NVD
CVE-2026-31052 MEDIUM - 5.3

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow component

Published: Apr 24, 2026
Source: NVD

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component

Published: Apr 24, 2026
Source: NVD
CVE-2026-31050 MEDIUM - 4.9

Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code

Published: Apr 24, 2026
Source: NVD
CVE-2025-61872 MEDIUM - 6.1

Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query p...

Published: Apr 24, 2026
Source: NVD
CVE-2026-25660 CRITICAL - 9.8

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls.  This bypass allows assigning arbitrary permission to any user existing in CodeCheck...

Vendor: Ericsson
Product: CodeChecker
Published: Apr 24, 2026
Source: NVD
CVE-2026-5367 HIGH - 8.6

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the...

Published: Apr 24, 2026
Source: NVD
CVE-2026-5265 MEDIUM - 6.5

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buff...

Published: Apr 24, 2026
Source: NVD
CVE-2026-40690 MEDIUM - 4.3

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are ...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 24, 2026
Source: NVD
CVE-2026-38743 MEDIUM - 4.3

The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for D...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 24, 2026
Source: NVD
CVE-2026-21515 CRITICAL - 9.9

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_iot_central
Published: Apr 24, 2026
Source: NVD

P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate existing users, authenticate to accounts with no password set, and access depot contents via the bui...

Published: Apr 24, 2026
Source: NVD

AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation by the server results in arbitrary JavaScript execution in the victim's browser. Critically, this...

Published: Apr 24, 2026
Source: NVD
CVE-2026-23902 HIGH - 8.1

Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1.  Users are recommended to upg...

Vendor: Apache Software Foundation
Product: Apache DolphinScheduler
Published: Apr 24, 2026
Source: NVD
CVE-2026-41044 HIGH - 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validati...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All
Published: Apr 24, 2026
Source: NVD
CVE-2026-41043 MEDIUM - 6.5

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecti...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ, Apache ActiveMQ Web
Published: Apr 24, 2026
Source: NVD
CVE-2026-40466 HIGH - 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via ...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
Published: Apr 24, 2026
Source: NVD
CVE-2025-62233 MEDIUM - 6.3

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malic...

Vendor: Apache Software Foundation
Product: Apache DolphinScheduler
Published: Apr 24, 2026
Source: NVD

A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open Open...

Published: Apr 24, 2026
Source: NVD