Total CVEs

126,161

Critical Severity

2,292

High Severity

7,941

Last 7 Days

1,206
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,181 - 1,200 of 22,566 CVEs
CVE-2026-41572 MEDIUM - 5.3

Note Mark: Unauthenticated read of notes and assets in soft-deleted public books

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-41571 CRITICAL - 9.4

Note Mark: OIDC-registered users authenticated by submitting password "null"

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-41520 HIGH - 7.9

Cillium exposes sensitive information included in the cilium-bugtool debug archive

Vendor: go
Product: github.com/cilium/cilium
Published: Apr 25, 2026
Source: GitHub
CVE-2026-7002 HIGH - 7.3

A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the at...

Published: Apr 25, 2026
Source: NVD
CVE-2026-7001 LOW - 2.4

A vulnerability was found in Datacom DM4100 1.3.6.1.4.1.3709. This affects an unknown part of the component Ethernet Configuration Page. Performing a manipulation of the argument Name results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public an...

Published: Apr 25, 2026
Source: NVD
CVE-2026-7000 LOW - 2.4

A vulnerability has been found in Datacom DM4100 1.3.6.1.4.1.3709. Affected by this issue is some unknown functionality of the component VLAN Page. Such manipulation of the argument VLAN Name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to th...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6999 LOW - 2.4

A flaw has been found in BIVOCOM TR321 21.1.1.50. Affected by this vulnerability is an unknown functionality of the component Wireless Setting. This manipulation of the argument Network Name SSID causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been pub...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6998 LOW - 2.4

A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. T...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6997 LOW - 2.4

A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been dis...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6996 LOW - 2.4

A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6995 LOW - 2.4

A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipulation of the argument User name results in cross site scripting. The attack may be initiated remotely....

Published: Apr 25, 2026
Source: NVD
CVE-2026-6994 MEDIUM - 6.3

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch n...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6993 MEDIUM - 5.3

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6992 HIGH - 7.2

A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remote...

Vendor: linksys
Product: mr9600_firmware
Published: Apr 25, 2026
Source: NVD
CVE-2026-6991 MEDIUM - 6.3

A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has ...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6990 LOW - 3.5

A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descriรงรฃo results in cross site scripting. The attack can be initiated remotely. The exploit has been made pu...

Published: Apr 25, 2026
Source: NVD
CVE-2026-6989 MEDIUM - 6.3

A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ma...

Vendor: tenda
Product: f453_firmware
Published: Apr 25, 2026
Source: NVD
CVE-2026-6988 HIGH - 8.8

A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the argument nextHop causes buffer overflow. It is possible to initiate the attack remotely. The exploit...

Vendor: tenda
Product: hg10_firmware
Published: Apr 25, 2026
Source: NVD
CVE-2026-6987 HIGH - 7.3

A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of t...

Vendor: sipeed
Product: picoclaw
Published: Apr 25, 2026
Source: NVD
CVE-2026-6986 LOW - 3.7

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be ...

Vendor: cesanta
Product: mongoose
Published: Apr 25, 2026
Source: NVD