Total CVEs

125,681

Critical Severity

2,261

High Severity

7,827

Last 7 Days

1,162
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,061 - 1,080 of 22,086 CVEs
CVE-2026-32210 CRITICAL - 9.3

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 23, 2026
Source: NVD
CVE-2026-32172 HIGH - 8.0

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: power_apps
Published: Apr 23, 2026
Source: NVD
CVE-2026-2708 LOW - 3.7

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-26210 CRITICAL - 9.8

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can s...

Vendor: kvcache-ai
Product: ktransformers
Published: Apr 23, 2026
Source: NVD
CVE-2026-26150 HIGH - 8.6

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: purview_ediscovery
Published: Apr 23, 2026
Source: NVD
CVE-2026-24303 CRITICAL - 9.6

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: partner_center
Published: Apr 23, 2026
Source: NVD
CVE-2026-29051 MEDIUM - 4.4

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) constructs output file paths by joining `--out-dir` with the `ar...

Vendor: go
Product: chainguard.dev/melange
Published: Apr 23, 2026
Source: GitHub
CVE-2026-29050 MEDIUM - 6.1

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuration file โ€” for example through pull-request-driven CI or build-as-a-service scenarios โ€” could set `pipeline[].uses` to a v...

Vendor: go
Product: chainguard.dev/melange
Published: Apr 23, 2026
Source: GitHub

@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default redirect: 'follow' behavior. This allows the Cloudflare Worker to fo...

Vendor: npm
Product: @astrojs/cloudflare
Published: Apr 23, 2026
Source: GitHub
CVE-2026-41900 HIGH - 8.8

OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment

Vendor: npm
Product: openlearnx
Published: Apr 23, 2026
Source: GitHub
CVE-2026-41173 MEDIUM - 5.9

The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.Sampler.AWS reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory. AWSXRaySamplerClient.DoRequestAsync ...

Vendor: nuget
Product: OpenTelemetry.Sampler.AWS
Published: Apr 23, 2026
Source: GitHub
CVE-2026-40894 MEDIUM - 5.3

OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet...

Vendor: nuget
Product: OpenTelemetry.Api
Published: Apr 23, 2026
Source: GitHub
CVE-2026-40886 HIGH - 7.7

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj....

Vendor: go
Product: github.com/argoproj/argo-workflows/v4
Published: Apr 23, 2026
Source: GitHub
CVE-2026-40099 MEDIUM - 6.5

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also possible to custom...

Vendor: composer
Product: getkirby/cms
Published: Apr 23, 2026
Source: GitHub
CVE-2026-34587 HIGH - 8.1

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/....

Vendor: composer
Product: getkirby/cms
Published: Apr 23, 2026
Source: GitHub
CVE-2026-33318 HIGH - 8.8

Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `POST /account/change-password` has no authorization check, al...

Vendor: npm
Product: @actual-app/sync-server
Published: Apr 23, 2026
Source: GitHub
CVE-2026-32952 MEDIUM - 5.3

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.

Vendor: go
Product: github.com/Azure/go-ntlmssp
Published: Apr 23, 2026
Source: GitHub
CVE-2026-32870 MEDIUM - 7.5

Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a second time but allowed to pass through. However, prior to versions 4.9.0 and 5.4.0, it was po...

Vendor: composer
Product: getkirby/cms
Published: Apr 23, 2026
Source: GitHub
CVE-2026-6942 CRITICAL - 9.8

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters thro...

Published: Apr 23, 2026
Source: NVD
CVE-2026-6941 MEDIUM - 6.6

radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a sy...

Vendor: radare
Product: radare2
Published: Apr 23, 2026
Source: NVD