Total CVEs

126,186

Critical Severity

2,292

High Severity

7,951

Last 7 Days

1,204
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,301 - 1,320 of 22,591 CVEs
CVE-2026-6911 CRITICAL - 9.8

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the dep...

Published: Apr 24, 2026
Source: NVD
CVE-2026-41411 MEDIUM - 6.6

Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the file...

Vendor: vim
Product: vim
Published: Apr 24, 2026
Source: NVD
CVE-2026-41079 MEDIUM - 4.3

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is c...

Vendor: OpenPrinting
Product: cups
Published: Apr 24, 2026
Source: NVD
CVE-2026-40912 HIGH - 8.2

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The middleware matche...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub

Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution

Vendor: npm
Product: @anthropic-ai/claude-code
Published: Apr 24, 2026
Source: GitHub
CVE-2026-39858 HIGH - 10.0

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic targets on...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub
CVE-2026-35051 HIGH - 10.0

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This is...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Apr 24, 2026
Source: GitHub
CVE-2026-33524 HIGH - 7.5

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). This vulnerability is fixed in 2...

Vendor: maven
Product: io.github.ndsev:zserio-runtime
Published: Apr 24, 2026
Source: GitHub

Kimai has Missing Object-Level Authorization in the Team API

Vendor: composer
Product: kimai/kimai
Published: Apr 24, 2026
Source: GitHub

Rejected reason: This CVE is a duplicate of another CVE.

Published: Apr 24, 2026
Source: NVD
CVE-2026-39920 CRITICAL - 9.8

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console us...

Vendor: BridgeHead Software
Product: FileStore
Published: Apr 24, 2026
Source: NVD
CVE-2026-30368 MEDIUM - 5.4

A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.

Published: Apr 24, 2026
Source: NVD
CVE-2025-67259 MEDIUM - 6.5

A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized course-level information by modifying intercepted API requests. Changing a captured POST request to a GET request against the /rest/v1/course Pos...

Published: Apr 24, 2026
Source: NVD
CVE-2025-59308 MEDIUM - 4.7

In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

Published: Apr 24, 2026
Source: NVD
CVE-2026-41492 CRITICAL - 9.8

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker ...

Vendor: go
Product: github.com/dgraph-io/dgraph/v25
Published: Apr 24, 2026
Source: GitHub

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Vendor: pip
Product: ray
Published: Apr 24, 2026
Source: GitHub
CVE-2026-41432 HIGH - 7.1

New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud

Vendor: go
Product: github.com/QuantumNous/new-api
Published: Apr 24, 2026
Source: GitHub
CVE-2026-41328 CRITICAL - 9.1

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack requi...

Vendor: go
Product: github.com/dgraph-io/dgraph/v25
Published: Apr 24, 2026
Source: GitHub
CVE-2026-41327 CRITICAL - 9.1

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack is a ...

Vendor: go
Product: github.com/dgraph-io/dgraph/v25
Published: Apr 24, 2026
Source: GitHub
CVE-2026-41311 HIGH - 7.5

liquidjs has a Denial of Service via circular block reference in layout

Vendor: npm
Product: liquidjs
Published: Apr 24, 2026
Source: GitHub