Total CVEs

125,728

Critical Severity

2,261

High Severity

7,831

Last 7 Days

1,201
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,241 - 1,260 of 22,133 CVEs
CVE-2026-41206 HIGH - 7.8

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The plugin security validator in PySpector uses AST-based static analysis to prevent dangerous code from being loaded as plugins. Prior to version 0.1.8, the blocklist implemented in ...

Vendor: ParzivalHack
Product: PySpector
Published: Apr 23, 2026
Source: NVD

STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scripting (XSS) vulnerability in the OIDC authentication error handling code in `src/init.js` and `public/...

Vendor: NUWCDIVNPT
Product: stig-manager
Published: Apr 23, 2026
Source: NVD

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device. This applies to th...

Vendor: luanti-org
Product: luanti
Published: Apr 23, 2026
Source: NVD
CVE-2026-41182 MEDIUM - 5.3

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token eve...

Vendor: langchain-ai
Product: langsmith-sdk
Published: Apr 23, 2026
Source: NVD
CVE-2026-41180 HIGH - 7.5

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `req.path`, but the downstream tus handler later writes using the decoded `req.params.uploadId`. In depl...

Vendor: psi-4ward
Product: psitransfer
Published: Apr 23, 2026
Source: NVD
CVE-2026-1923 MEDIUM - 6.4

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ā€˜id’ parameter in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscr...

Published: Apr 23, 2026
Source: NVD
CVE-2026-6878 MEDIUM - 5.6

A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be di...

Published: Apr 23, 2026
Source: NVD
CVE-2026-6874 MEDIUM - 4.3

A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing a manipulation of the argument Host can lead to reliance on reverse dns resolution. The attack may be performed from remote. The exploit ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-5935 HIGH - 7.3

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMCĀ could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

Published: Apr 23, 2026
Source: NVD
CVE-2026-5926 MEDIUM - 6.5

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 uses weaker than expected cryptographic algorithms that could allow an attac...

Published: Apr 23, 2026
Source: NVD
CVE-2026-4919 MEDIUM - 4.8

IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2026-4918 MEDIUM - 5.5

IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2026-4917 MEDIUM - 4.9

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2026-40062 HIGH - 7.5

A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the operating system.

Vendor: Ziosoft, Inc.
Product: Ziostation2
Published: Apr 23, 2026
Source: NVD
CVE-2026-3621 HIGH - 7.5

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

Published: Apr 23, 2026
Source: NVD
CVE-2026-32679 HIGH - 7.8

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at th...

Vendor: Japan Media Systems Corporation
Product: Downloader5Installer.exe, Downloader5InstallerForAdmin.exe, CanonNWCamPlugin.exe, CanonNWCamPluginForAdmin.exe
Published: Apr 23, 2026
Source: NVD
CVE-2026-29198 CRITICAL - 9.8

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Apr 23, 2026
Source: NVD
CVE-2026-1726 MEDIUM - 4.8

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1

Vendor: ibm
Product: guardium_key_lifecycle_manager
Published: Apr 23, 2026
Source: NVD
CVE-2026-1352 MEDIUM - 6.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow anĀ authenticated user to cause a denial of service due to improper neutralization of specialĀ elements in data query logic.

Vendor: ibm
Product: db2
Published: Apr 23, 2026
Source: NVD
CVE-2026-1274 MEDIUM - 4.9

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD