Total CVEs

125,728

Critical Severity

2,261

High Severity

7,831

Last 7 Days

1,199
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,261 - 1,280 of 22,133 CVEs
CVE-2026-1272 LOW - 2.7

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2025-36074 MEDIUM - 5.5

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against ...

Vendor: IBM
Product: Security Verify Directory (Container)
Published: Apr 23, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Apr 22, 2026
Source: NVD
CVE-2026-41455 HIGH - 8.5

WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the url schema field accepts any string without protocol restriction or destination validation. Attackers who can create or modify integrations can set webhook URLs to internal network ad...

Vendor: wekan
Product: wekan
Published: Apr 22, 2026
Source: NVD
CVE-2026-41454 HIGH - 8.3

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations...

Vendor: wekan
Product: wekan
Published: Apr 22, 2026
Source: NVD
CVE-2026-41314 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values. This has been fixed in pypdf 6.10.2....

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41313 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. This has been fixed in pypdf 6.10.2. As ...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41312 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/Predictor` unequal 1 and large predictor...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41177 MEDIUM - 5.5

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-supplied `Url` parameter, allowing the use...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD
CVE-2026-41175 HIGH - 8.1

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requi...

Vendor: statamic
Product: cms
Published: Apr 22, 2026
Source: NVD

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private network targets, and persist the response as an ...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD

Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP client used by scripting engine functions (`getJSON`, `request`, etc.). An authe...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for downloading backup archives. This URL is fetched using the "Backup" `Http...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD
CVE-2026-40517 HIGH - 7.8

radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsa...

Vendor: radareorg
Product: radare2
Published: Apr 22, 2026
Source: NVD
CVE-2026-41511 MEDIUM - 6.2

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle

Vendor: nuget
Product: OpenMcdf
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41676 HIGH - 9.8

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-e...

Vendor: rust
Product: openssl
Published: Apr 22, 2026
Source: GitHub

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions...

Vendor: rust
Product: openssl
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41678 HIGH - 9.8

rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the o...

Vendor: rust
Product: openssl
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41168 MEDIUM - 5.3

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This h...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41167 CRITICAL - 9.1

Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails...

Vendor: CyferShepard
Product: Jellystat
Published: Apr 22, 2026
Source: NVD