Total CVEs

125,743

Critical Severity

2,263

High Severity

7,843

Last 7 Days

1,200
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,321 - 1,340 of 22,148 CVEs
CVE-2026-41646 MEDIUM - 5.5

Nuclei: Local File Read via require() Module Loader Bypass

Vendor: go
Product: github.com/projectdiscovery/nuclei/v3
Published: Apr 22, 2026
Source: GitHub

monetr: Server-side request forgery in Lunch Flow link creation and refresh

Vendor: go
Product: github.com/monetr/monetr
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41591 MEDIUM - 6.4

Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping

Vendor: npm
Product: marko
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41469 MEDIUM - 5.2

Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP rem...

Vendor: Beghelli
Product: SicuroWeb (Sicuro24)
Published: Apr 22, 2026
Source: NVD
CVE-2026-41468 HIGH - 8.7

Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution ...

Vendor: Beghelli
Product: SicuroWeb (Sicuro24)
Published: Apr 22, 2026
Source: NVD
CVE-2026-41459 MEDIUM - 5.3

Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the exposed root_path value re...

Vendor: thexerteproject
Product: xerteonlinetoolkits
Published: Apr 22, 2026
Source: NVD
CVE-2026-34415 CRITICAL - 9.8

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication ...

Vendor: thexerteproject
Product: xerteonlinetoolkits
Published: Apr 22, 2026
Source: NVD
CVE-2026-34414 HIGH - 7.1

Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in rename commands is not sanitized for path traversal sequences. Attackers can supply a name value contai...

Vendor: thexerteproject
Product: xerteonlinetoolkits
Published: Apr 22, 2026
Source: NVD
CVE-2026-34413 HIGH - 8.6

Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the ...

Vendor: thexerteproject
Product: xerteonlinetoolkits
Published: Apr 22, 2026
Source: NVD
CVE-2026-28950 MEDIUM - 6.2

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2. Notifications marked for deletion could be unexpectedly retained on the device.

Vendor: Apple
Product: iOS and iPadOS
Published: Apr 22, 2026
Source: NVD
CVE-2026-26354 HIGH - 8.1

Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer Overflow vulnerability. An unauthenticated attacker ...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 22, 2026
Source: NVD
CVE-2026-41422 HIGH - 8.3

Daptin: SQL injection via unvalidated goqu.L() calls in aggregate API

Vendor: go
Product: github.com/daptin/daptin
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41240 MEDIUM - 6.1

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not app...

Vendor: npm
Product: dompurify
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41239 MEDIUM - 6.8

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS v...

Vendor: npm
Product: dompurify
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41238 MEDIUM - 6.9

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior proto...

Vendor: npm
Product: dompurify
Published: Apr 22, 2026
Source: GitHub

CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 22, 2026
Source: GitHub

CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 22, 2026
Source: GitHub
CVE-2026-41201 MEDIUM - 6.8

CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 22, 2026
Source: GitHub
CVE-2026-6515 MEDIUM - 5.4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

Vendor: gitlab
Product: gitlab
Published: Apr 22, 2026
Source: NVD
CVE-2026-5816 HIGH - 8.0

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.

Vendor: gitlab
Product: gitlab
Published: Apr 22, 2026
Source: NVD