Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
Showing 1,301 - 1,320 of 3,557 CVEs
CVE-2026-26015 CRITICAL - 9.8

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execut...

Vendor: arc53
Product: DocsGPT
Published: Apr 29, 2026
Source: NVD
CVE-2026-5166 CRITICAL - 9.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. This issue affects Pardus Software Center: before 1.0.3.

Published: Apr 29, 2026
Source: NVD
CVE-2026-41940 CRITICAL - 9.8

cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Vendor: cPanel, L.L.C.
Product: cPanel & WHM, WP Squared
Published: Apr 29, 2026
Source: NVD
CVE-2026-38992 CRITICAL - 9.8

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.

Published: Apr 29, 2026
Source: NVD
CVE-2026-36841 CRITICAL - 9.8

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.

Published: Apr 29, 2026
Source: NVD
CVE-2026-5140 CRITICAL - 9.6

Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass. This issue affects Pardus Update: from 0.6.3 before 0.6.4.

Published: Apr 29, 2026
Source: NVD
CVE-2026-42523 CRITICAL - 9.0

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers wit...

Vendor: Jenkins Project
Product: Jenkins GitHub Plugin
Published: Apr 29, 2026
Source: NVD
CVE-2026-7343 CRITICAL - 9.8

Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: Apr 28, 2026
Source: NVD
CVE-2026-7333 CRITICAL - 9.6

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 28, 2026
Source: NVD
CVE-2026-41446 CRITICAL - 9.8

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device ...

Vendor: Snap One, LLC
Product: WattBox 800, WattBox 820
Published: Apr 28, 2026
Source: NVD
CVE-2026-41386 CRITICAL - 9.1

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 28, 2026
Source: NVD
CVE-2026-3893 CRITICAL - 9.4

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials.

Published: Apr 28, 2026
Source: NVD
CVE-2026-24178 CRITICAL - 9.8

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information di...

Vendor: NVIDIA
Product: FLARE SDK
Published: Apr 28, 2026
Source: NVD
CVE-2026-41873 CRITICAL - 9.8

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under dev...

Vendor: apache
Product: pony_mail
Published: Apr 28, 2026
Source: NVD
CVE-2025-60889 CRITICAL - 9.8

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7321 CRITICAL - 9.6

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.

Vendor: mozilla
Product: firefox
Published: Apr 28, 2026
Source: NVD
CVE-2026-7248 CRITICAL - 9.8

A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Vendor: dlink
Product: di-8100_firmware
Published: Apr 28, 2026
Source: NVD
CVE-2026-7244 CRITICAL - 9.8

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge results in os command injection. It is possible to launch the at...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7243 CRITICAL - 9.8

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is possible to initiate the att...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7242 CRITICAL - 9.8

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may be performed from remo...

Published: Apr 28, 2026
Source: NVD