Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,948
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,341 - 1,360 of 3,419 CVEs
CVE-2026-41635 CRITICAL - 9.8

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted clas...

Vendor: Apache Software Foundation
Product: Apache MINA
Published: Apr 27, 2026
Source: NVD
CVE-2026-40860 CRITICAL - 9.8

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is ...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Apr 27, 2026
Source: NVD
CVE-2026-40453 CRITICAL - 9.9

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP Header...

Vendor: Apache Software Foundation
Product: Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub
Published: Apr 27, 2026
Source: NVD
CVE-2026-42363 CRITICAL - 9.3

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various...

Vendor: GeoVision Inc.
Product: GV-IP Device Utility
Published: Apr 27, 2026
Source: NVD
CVE-2026-7037 CRITICAL - 9.8

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru results in os command injection. The attack can be executed remotely...

Published: Apr 26, 2026
Source: NVD
CVE-2026-41571 CRITICAL - 9.4

Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits pass...

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-31685 CRITICAL - 9.4

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of the IPv6 source address. The existing guard only re...

Vendor: Linux
Product: Linux
Published: Apr 25, 2026
Source: NVD
CVE-2026-31682 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and assumes that these options are in the linear part of request. Its callers only guarantee that the I...

Vendor: Linux
Product: Linux
Published: Apr 25, 2026
Source: NVD
CVE-2026-6951 CRITICAL - 9.8

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the optio...

Published: Apr 25, 2026
Source: NVD
CVE-2026-41478 CRITICAL - 9.9

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcornโ€™s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through syn...

Vendor: saltcorn
Product: saltcorn
Published: Apr 24, 2026
Source: NVD
CVE-2026-41473 CRITICAL - 9.1

CyberPanel versions prior toย 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoin...

Vendor: usmannasir
Product: cyberpanel
Published: Apr 24, 2026
Source: NVD
CVE-2026-41248 CRITICAL - 9.1

Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @cler...

Vendor: clerk
Product: astro, nextjs, nuxt, shared
Published: Apr 24, 2026
Source: NVD
CVE-2026-41501 CRITICAL - 9.8

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:130. The runLinux() function appends attacker-controlled remote version strings directly into an ex...

Vendor: npm
Product: electerm
Published: Apr 24, 2026
Source: GitHub
CVE-2026-41475 CRITICAL - 9.1

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated...

Vendor: bacnet-stack
Product: bacnet-stack
Published: Apr 24, 2026
Source: NVD
CVE-2026-41428 CRITICAL - 9.1

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the query string, an attacker can access any protected endpoint b...

Vendor: Budibase
Product: budibase
Published: Apr 24, 2026
Source: NVD
CVE-2026-41415 CRITICAL - 9.1

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerabili...

Vendor: pjsip
Product: pjproject
Published: Apr 24, 2026
Source: NVD
CVE-2026-6911 CRITICAL - 9.8

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the dep...

Published: Apr 24, 2026
Source: NVD
CVE-2026-39920 CRITICAL - 9.8

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console us...

Vendor: BridgeHead Software
Product: FileStore
Published: Apr 24, 2026
Source: NVD
CVE-2026-41492 CRITICAL - 9.8

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker ...

Vendor: go
Product: github.com/dgraph-io/dgraph/v25
Published: Apr 24, 2026
Source: GitHub
CVE-2026-41328 CRITICAL - 9.1

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack requi...

Vendor: go
Product: github.com/dgraph-io/dgraph/v25
Published: Apr 24, 2026
Source: GitHub