Total CVEs

125,743

Critical Severity

2,263

High Severity

7,843

Last 7 Days

1,200
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,241 - 1,260 of 22,148 CVEs
CVE-2026-41233 MEDIUM - 5.4

Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling reseller does not have the `customers_see_all` permission. This allows a reseller to attribute newly cre...

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-41232 MEDIUM - 5.0

Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to `validateLocalDomainOwner...

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-40529 MEDIUM - 4.7

CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.

Vendor: KANATA Limited
Product: CMS ALAYA
Published: Apr 23, 2026
Source: NVD
CVE-2026-41231 HIGH - 7.5

Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter to `FileDir::makeCorrectDir()`, bypassing the symlink validation that was added to all other ...

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-41230 HIGH - 8.5

Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in the `content` field. When a DNS type not covered by the if/elseif validation chain is submitted (e.g....

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-41229 CRITICAL - 9.1

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a MySQL server via the AP...

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-41228 CRITICAL - 9.9

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set `def_language` to a path tra...

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-3361 MEDIUM - 6.4

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and including, 2.2.261 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr...

Published: Apr 23, 2026
Source: NVD
CVE-2026-3007 MEDIUM - 5.4

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMSโ€™ courselet feature.

Published: Apr 23, 2026
Source: NVD
CVE-2026-3844 CRITICAL - 9.8

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-2951 MEDIUM - 5.4

The Gutentor โ€“ Gutenberg Blocks โ€“ Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut...

Published: Apr 23, 2026
Source: NVD
CVE-2026-41679 CRITICAL - 10.0

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration....

Vendor: paperclipai
Product: paperclip, @paperclipai/server
Published: Apr 23, 2026
Source: NVD
CVE-2026-41243 MEDIUM - 5.4

OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the direct post-read procedure still returns the full post to anyone with the post UUID. Commit 844b2...

Vendor: siemvk
Product: OpenLearn
Published: Apr 23, 2026
Source: NVD
CVE-2026-41211 CRITICAL - 10.0

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm&g...

Vendor: voidzero-dev
Product: vite-plus
Published: Apr 23, 2026
Source: NVD
CVE-2026-41208 HIGH - 8.8

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server ...

Vendor: paperclipai
Product: @paperclipai/server
Published: Apr 23, 2026
Source: NVD
CVE-2026-41206 HIGH - 7.8

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The plugin security validator in PySpector uses AST-based static analysis to prevent dangerous code from being loaded as plugins. Prior to version 0.1.8, the blocklist implemented in ...

Vendor: ParzivalHack
Product: PySpector
Published: Apr 23, 2026
Source: NVD

STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scripting (XSS) vulnerability in the OIDC authentication error handling code in `src/init.js` and `public/...

Vendor: NUWCDIVNPT
Product: stig-manager
Published: Apr 23, 2026
Source: NVD

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device. This applies to th...

Vendor: luanti-org
Product: luanti
Published: Apr 23, 2026
Source: NVD
CVE-2026-41182 MEDIUM - 5.3

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token eve...

Vendor: langchain-ai
Product: langsmith-sdk
Published: Apr 23, 2026
Source: NVD
CVE-2026-41180 HIGH - 7.5

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `req.path`, but the downstream tus handler later writes using the decoded `req.params.uploadId`. In depl...

Vendor: psi-4ward
Product: psitransfer
Published: Apr 23, 2026
Source: NVD