Total CVEs

125,728

Critical Severity

2,261

High Severity

7,831

Last 7 Days

1,201
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,021 - 1,040 of 22,133 CVEs
CVE-2026-21728 HIGH - 7.5

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).

Vendor: Grafana
Product: Tempo
Published: Apr 24, 2026
Source: NVD
CVE-2026-4078 MEDIUM - 6.4

The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-login, iteras-selfservice) in all versions up to and including 1.8.2. This is due to insufficient input sanitization and output escaping in the combine...

Published: Apr 24, 2026
Source: NVD
CVE-2026-3569 MEDIUM - 5.3

The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally returns true (via __return_true()) instead of checking for a...

Published: Apr 24, 2026
Source: NVD
CVE-2026-3565 MEDIUM - 4.3

The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to a missing nonce verification in the taqnix_delete_my_account() function, where the check_ajax_referer() call is explicitly commented out on line 883. This makes it ...

Published: Apr 24, 2026
Source: NVD
CVE-2025-11762 MEDIUM - 4.3

The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contribut...

Vendor: hubspotdev
Product: HubSpot All-In-One Marketing – Forms, Popups, Live Chat
Published: Apr 24, 2026
Source: NVD
CVE-2026-1952 CRITICAL - 9.8

Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

Published: Apr 24, 2026
Source: NVD
CVE-2026-1951 CRITICAL - 9.8

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

Published: Apr 24, 2026
Source: NVD
CVE-2026-1950 CRITICAL - 9.8

Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.

Published: Apr 24, 2026
Source: NVD
CVE-2026-6810 MEDIUM - 5.3

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated att...

Published: Apr 24, 2026
Source: NVD
CVE-2026-5428 MEDIUM - 6.4

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post()...

Published: Apr 24, 2026
Source: NVD
CVE-2026-5364 HIGH - 8.1

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attack...

Published: Apr 24, 2026
Source: NVD
CVE-2026-5347 MEDIUM - 5.3

The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of capability checks and nonce verification in the admin_init hook that handles the permalink settings update at line 205-209 of wp-books-gallery.php. Th...

Published: Apr 24, 2026
Source: NVD
CVE-2026-1949 CRITICAL - 9.8

Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.

Published: Apr 24, 2026
Source: NVD
CVE-2026-6947 HIGH - 7.5

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device.

Published: Apr 24, 2026
Source: NVD
CVE-2026-6393 MEDIUM - 4.3

The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possib...

Published: Apr 24, 2026
Source: NVD
CVE-2026-5488 MEDIUM - 5.3

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is loca...

Published: Apr 24, 2026
Source: NVD
CVE-2026-41485 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller ...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected XSS. The patch in commit 16d1b6ca2559f858a1de77bcb03fd7f1b81671c6 fixes the issue by restricting redirec...

Vendor: frappe
Product: press
Published: Apr 24, 2026
Source: NVD
CVE-2026-41324 HIGH - 7.5

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client....

Vendor: patrickjuchli
Product: basic-ftp
Published: Apr 24, 2026
Source: NVD
CVE-2026-41323 HIGH - 8.1

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service UR...

Vendor: kyverno
Product: kyverno
Published: Apr 24, 2026
Source: NVD