Total CVEs

125,743

Critical Severity

2,263

High Severity

7,843

Last 7 Days

1,178
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,281 - 1,300 of 22,148 CVEs
CVE-2026-41314 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values. This has been fixed in pypdf 6.10.2....

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41313 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. This has been fixed in pypdf 6.10.2. As ...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41312 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/Predictor` unequal 1 and large predictor...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41177 MEDIUM - 5.5

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-supplied `Url` parameter, allowing the use...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD
CVE-2026-41175 HIGH - 8.1

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requi...

Vendor: statamic
Product: cms
Published: Apr 22, 2026
Source: NVD

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private network targets, and persist the response as an ...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD

Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP client used by scripting engine functions (`getJSON`, `request`, etc.). An authe...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for downloading backup archives. This URL is fetched using the "Backup" `Http...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD
CVE-2026-40517 HIGH - 7.8

radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsa...

Vendor: radareorg
Product: radare2
Published: Apr 22, 2026
Source: NVD
CVE-2026-41511 MEDIUM - 6.2

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle

Vendor: nuget
Product: OpenMcdf
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41676 HIGH - 9.8

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-e...

Vendor: rust
Product: openssl
Published: Apr 22, 2026
Source: GitHub

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions...

Vendor: rust
Product: openssl
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41678 HIGH - 9.8

rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the o...

Vendor: rust
Product: openssl
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41168 MEDIUM - 5.3

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This h...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41167 CRITICAL - 9.1

Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails...

Vendor: CyferShepard
Product: Jellystat
Published: Apr 22, 2026
Source: NVD

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template metadata, enum/property metadata, an...

Vendor: microsoft
Product: kiota
Published: Apr 22, 2026
Source: NVD
CVE-2026-40937 HIGH - 8.3

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a `check_permissions` helper that validates authentication only (access key + session token), without performing any admi...

Vendor: rustfs
Product: rustfs
Published: Apr 22, 2026
Source: NVD

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter implementations interpolate stored values into raw HTML attributes and element content without escapin...

Published: Apr 22, 2026
Source: NVD
CVE-2026-34068 MEDIUM - 6.8

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_voting_key=Some(...)` while omitting `new_proof_of_knowledge`. this skips the proof-of-knowledge requ...

Vendor: nimiq
Product: nimiq-transaction
Published: Apr 22, 2026
Source: NVD

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` panics on a malformed proof where `history.len() != positions.len()` due to `assert_eq!(history.len(), positions.len())`. The proof object is derive...

Vendor: nimiq
Product: nimiq-transaction
Published: Apr 22, 2026
Source: NVD