Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,920
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,381 - 1,400 of 3,419 CVEs
CVE-2026-33078 CRITICAL - 9.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through m...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-33076 CRITICAL - 9.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing into scheduled tasks. Version 8.2.6.4 fixes the issu...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 24, 2026
Source: NVD
CVE-2026-40630 CRITICAL - 9.8

A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may be able to bypass the intended authentication mechanism and directly interact w...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-40620 CRITICAL - 9.8

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted mod...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-35503 CRITICAL - 9.8

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. An attacker with access to the login page could retrieve these expo...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-27843 CRITICAL - 9.1

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying unsupported or disruptive values to recovery mechanisms and network settings, an attacker ca...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-25775 CRITICAL - 9.8

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded ima...

Vendor: SenseLive
Product: X3050
Published: Apr 24, 2026
Source: NVD
CVE-2026-35431 CRITICAL - 10.0

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

Vendor: microsoft
Product: entra_id
Published: Apr 23, 2026
Source: NVD
CVE-2026-33819 CRITICAL - 10.0

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Published: Apr 23, 2026
Source: NVD
CVE-2026-33102 CRITICAL - 9.3

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: 365_copilot
Published: Apr 23, 2026
Source: NVD
CVE-2026-32210 CRITICAL - 9.3

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 23, 2026
Source: NVD
CVE-2026-26210 CRITICAL - 9.8

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can s...

Vendor: kvcache-ai
Product: ktransformers
Published: Apr 23, 2026
Source: NVD
CVE-2026-24303 CRITICAL - 9.6

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: partner_center
Published: Apr 23, 2026
Source: NVD
CVE-2026-6942 CRITICAL - 9.8

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters thro...

Published: Apr 23, 2026
Source: NVD
CVE-2026-41276 CRITICAL - 9.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not required to exploit this vulnerability. The specific ...

Vendor: FlowiseAI
Product: Flowise
Published: Apr 23, 2026
Source: NVD
CVE-2026-41265 CRITICAL - 9.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt ...

Vendor: FlowiseAI
Product: Flowise
Published: Apr 23, 2026
Source: NVD
CVE-2026-25874 CRITICAL - 9.8

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attac...

Vendor: Hugging Face
Product: LeRobot
Published: Apr 23, 2026
Source: NVD
CVE-2026-41247 CRITICAL - 9.8

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In co...

Vendor: Studio-42
Product: elFinder
Published: Apr 23, 2026
Source: NVD
CVE-2026-6919 CRITICAL - 9.6

Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 23, 2026
Source: NVD
CVE-2026-31533 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto requests"), has a use-after-fre...

Vendor: Linux
Product: Linux
Published: Apr 23, 2026
Source: NVD