Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,903
Quick preset (or use dates below)
Clear Filters
Showing 1,401 - 1,420 of 3,557 CVEs
CVE-2026-33819 CRITICAL - 10.0

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Published: Apr 23, 2026
Source: NVD
CVE-2026-33102 CRITICAL - 9.3

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: 365_copilot
Published: Apr 23, 2026
Source: NVD
CVE-2026-32210 CRITICAL - 9.3

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Published: Apr 23, 2026
Source: NVD
CVE-2026-26210 CRITICAL - 9.8

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can s...

Vendor: kvcache-ai
Product: ktransformers
Published: Apr 23, 2026
Source: NVD
CVE-2026-24303 CRITICAL - 9.6

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: partner_center
Published: Apr 23, 2026
Source: NVD
CVE-2026-6942 CRITICAL - 9.8

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters thro...

Published: Apr 23, 2026
Source: NVD
CVE-2026-41276 CRITICAL - 9.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not required to exploit this vulnerability. The specific ...

Vendor: FlowiseAI
Product: Flowise
Published: Apr 23, 2026
Source: NVD
CVE-2026-41265 CRITICAL - 9.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt ...

Vendor: FlowiseAI
Product: Flowise
Published: Apr 23, 2026
Source: NVD
CVE-2026-25874 CRITICAL - 9.8

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attac...

Vendor: Hugging Face
Product: LeRobot
Published: Apr 23, 2026
Source: NVD
CVE-2026-41247 CRITICAL - 9.8

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In co...

Vendor: Studio-42
Product: elFinder
Published: Apr 23, 2026
Source: NVD
CVE-2026-6919 CRITICAL - 9.6

Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 23, 2026
Source: NVD
CVE-2026-31533 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto requests"), has a use-after-fre...

Vendor: Linux
Product: Linux
Published: Apr 23, 2026
Source: NVD
CVE-2026-31181 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31178 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31177 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31175 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-40472 CRITICAL - 9.9

In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.

Published: Apr 23, 2026
Source: NVD
CVE-2026-40471 CRITICAL - 9.6

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abuse...

Published: Apr 23, 2026
Source: NVD
CVE-2026-40470 CRITICAL - 9.9

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-39087 CRITICAL - 9.8

An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the parseActions function

Published: Apr 23, 2026
Source: NVD