Total CVEs

125,681

Critical Severity

2,261

High Severity

7,827

Last 7 Days

1,169
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,001 - 1,020 of 22,086 CVEs
CVE-2026-41305 MEDIUM - 6.1

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTM...

Vendor: postcss
Product: postcss
Published: Apr 24, 2026
Source: NVD
CVE-2026-40254 MEDIUM - 4.2

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but misses `..` when it's the last component with ...

Vendor: FreeRDP
Product: FreeRDP
Published: Apr 24, 2026
Source: NVD
CVE-2026-33317 HIGH - 8.7

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()` in `ta/pkcs11/src/object.c` can lead to out-of-bounds ...

Vendor: OP-TEE
Product: optee_os
Published: Apr 24, 2026
Source: NVD
CVE-2026-33208 HIGH - 8.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into a shell command string that is subsequently...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-33078 CRITICAL - 9.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through m...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-33077 HIGH - 7.5

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-33076 CRITICAL - 9.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing into scheduled tasks. Version 8.2.6.4 fixes the issu...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-41325 HIGH - 8.8

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also possible to custom...

Vendor: getkirby
Product: kirby
Published: Apr 24, 2026
Source: NVD
CVE-2026-31956 MEDIUM - 4.3

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview campaigns/regions, and export saved reports belonging to other users. Exploitation of the v...

Vendor: xibosignage
Product: xibo-cms
Published: Apr 24, 2026
Source: NVD
CVE-2026-31955 MEDIUM - 4.9

Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 4.4.1 allows users with DataSet permissions to make arbitrary HTTP requests from the CMS se...

Vendor: xibosignage
Product: xibo-cms
Published: Apr 24, 2026
Source: NVD
CVE-2026-31953 MEDIUM - 6.4

Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability in versions prior to 4.4.1 allows an authenticated user with notification creation permissions to inject arbitrary JavaScript in...

Vendor: xibosignage
Product: xibo-cms
Published: Apr 24, 2026
Source: NVD
CVE-2026-40630 CRITICAL - 9.8

A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may be able to bypass the intended authentication mechanism and directly interact w...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-40623 HIGH - 8.1

A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watc...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-40620 CRITICAL - 9.8

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted mod...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-40431 MEDIUM - 5.3

A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication attempts and configuration data, is transmitted in cleartext, an attacker with access to the same ne...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-39462 HIGH - 8.1

A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-35503 CRITICAL - 9.8

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. An attacker with access to the login page could retrieve these expo...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-35064 HIGH - 7.5

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and management interfaces without requiring credentials. Because discovery functions are exp...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-31952 HIGH - 7.6

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injection vulnerability in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain...

Vendor: xibosignage
Product: xibo-cms
Published: Apr 24, 2026
Source: NVD
CVE-2026-29197 MEDIUM - 4.3

In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing authenticated users without the proper permissions to read apps-engine lo...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Apr 24, 2026
Source: NVD