Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,853
Quick preset (or use dates below)
Clear Filters
Showing 1,281 - 1,300 of 3,547 CVEs
CVE-2025-14543 CRITICAL - 9.1

Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3...

Vendor: RTI
Product: Connext Professional
Published: Apr 30, 2026
Source: NVD
CVE-2026-35547 CRITICAL - 9.1

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to ex...

Vendor: FreeBSD
Product: FreeBSD
Published: Apr 30, 2026
Source: NVD
CVE-2026-7381 CRITICAL - 9.1

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Pl...

Published: Apr 29, 2026
Source: NVD
CVE-2026-42232 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pol...

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42231 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or mo...

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays witho...

Vendor: maven
Product: org.hyperledger.fabric-sdk-java:fabric-sdk-java
Published: Apr 29, 2026
Source: GitHub
CVE-2018-25318 CRITICAL - 9.8

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS serve...

Vendor: Tenda
Product: FH303/A300
Published: Apr 29, 2026
Source: NVD
CVE-2018-25317 CRITICAL - 9.8

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted ad...

Vendor: Tenda
Product: W3002R
Published: Apr 29, 2026
Source: NVD
CVE-2018-25316 CRITICAL - 9.8

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS ser...

Vendor: Tenda
Product: W, R v
Published: Apr 29, 2026
Source: NVD
CVE-2026-30893 CRITICAL - 9.0

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside t...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-26015 CRITICAL - 9.8

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execut...

Vendor: arc53
Product: DocsGPT
Published: Apr 29, 2026
Source: NVD
CVE-2026-5166 CRITICAL - 9.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. This issue affects Pardus Software Center: before 1.0.3.

Published: Apr 29, 2026
Source: NVD
CVE-2026-41940 CRITICAL - 9.8

cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Vendor: cPanel, L.L.C.
Product: cPanel & WHM, WP Squared
Published: Apr 29, 2026
Source: NVD
CVE-2026-38992 CRITICAL - 9.8

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.

Published: Apr 29, 2026
Source: NVD
CVE-2026-36841 CRITICAL - 9.8

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.

Published: Apr 29, 2026
Source: NVD
CVE-2026-5140 CRITICAL - 9.6

Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass. This issue affects Pardus Update: from 0.6.3 before 0.6.4.

Published: Apr 29, 2026
Source: NVD
CVE-2026-42523 CRITICAL - 9.0

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers wit...

Vendor: Jenkins Project
Product: Jenkins GitHub Plugin
Published: Apr 29, 2026
Source: NVD
CVE-2026-7343 CRITICAL - 9.8

Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: Apr 28, 2026
Source: NVD
CVE-2026-7333 CRITICAL - 9.6

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 28, 2026
Source: NVD
CVE-2026-41446 CRITICAL - 9.8

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device ...

Vendor: Snap One, LLC
Product: WattBox 800, WattBox 820
Published: Apr 28, 2026
Source: NVD