Total CVEs

125,728

Critical Severity

2,261

High Severity

7,831

Last 7 Days

1,199
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,101 - 1,120 of 22,133 CVEs
CVE-2026-41334 MEDIUM - 6.5

OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. Attackers can exploit this by uploading oversized images to cause denial of service through excessive memory consumption.

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 23, 2026
Source: NVD

OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute for...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 23, 2026
Source: NVD
CVE-2026-41332 MEDIUM - 5.3

OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration files...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 23, 2026
Source: NVD

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that a...

Vendor: FlowiseAI
Product: Flowise, flowise-components
Published: Apr 23, 2026
Source: NVD
CVE-2026-35431 CRITICAL - 10.0

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: entra_id
Published: Apr 23, 2026
Source: NVD
CVE-2026-33819 CRITICAL - 10.0

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Published: Apr 23, 2026
Source: NVD
CVE-2026-33102 CRITICAL - 9.3

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: 365_copilot
Published: Apr 23, 2026
Source: NVD
CVE-2026-32210 CRITICAL - 9.3

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 23, 2026
Source: NVD
CVE-2026-32172 HIGH - 8.0

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: power_apps
Published: Apr 23, 2026
Source: NVD
CVE-2026-2708 LOW - 3.7

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-26210 CRITICAL - 9.8

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can s...

Vendor: kvcache-ai
Product: ktransformers
Published: Apr 23, 2026
Source: NVD
CVE-2026-26150 HIGH - 8.6

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: purview_ediscovery
Published: Apr 23, 2026
Source: NVD
CVE-2026-24303 CRITICAL - 9.6

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: partner_center
Published: Apr 23, 2026
Source: NVD
CVE-2026-29051 MEDIUM - 4.4

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) constructs output file paths by joining `--out-dir` with the `ar...

Vendor: go
Product: chainguard.dev/melange
Published: Apr 23, 2026
Source: GitHub
CVE-2026-29050 MEDIUM - 6.1

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuration file โ€” for example through pull-request-driven CI or build-as-a-service scenarios โ€” could set `pipeline[].uses` to a v...

Vendor: go
Product: chainguard.dev/melange
Published: Apr 23, 2026
Source: GitHub

@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default redirect: 'follow' behavior. This allows the Cloudflare Worker to fo...

Vendor: npm
Product: @astrojs/cloudflare
Published: Apr 23, 2026
Source: GitHub
CVE-2026-41900 HIGH - 8.8

OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment

Vendor: npm
Product: openlearnx
Published: Apr 23, 2026
Source: GitHub
CVE-2026-41173 MEDIUM - 5.9

The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.Sampler.AWS reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory. AWSXRaySamplerClient.DoRequestAsync ...

Vendor: nuget
Product: OpenTelemetry.Sampler.AWS
Published: Apr 23, 2026
Source: GitHub
CVE-2026-40894 MEDIUM - 5.3

OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet...

Vendor: nuget
Product: OpenTelemetry.Api
Published: Apr 23, 2026
Source: GitHub
CVE-2026-40886 HIGH - 7.7

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj....

Vendor: go
Product: github.com/argoproj/argo-workflows/v4
Published: Apr 23, 2026
Source: GitHub