Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
Showing 1,421 - 1,440 of 3,561 CVEs
CVE-2026-40472 CRITICAL - 9.9

In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.

Published: Apr 23, 2026
Source: NVD
CVE-2026-40471 CRITICAL - 9.6

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abuse...

Published: Apr 23, 2026
Source: NVD
CVE-2026-40470 CRITICAL - 9.9

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-39087 CRITICAL - 9.8

An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the parseActions function

Published: Apr 23, 2026
Source: NVD
CVE-2026-23751 CRITICAL - 9.8

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauth...

Vendor: Tungsten Automation
Product: Kofax Capture
Published: Apr 23, 2026
Source: NVD
CVE-2025-62373 CRITICAL - 9.8

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integrat...

Vendor: pipecat-ai
Product: pipecat
Published: Apr 23, 2026
Source: NVD
CVE-2025-50229 CRITICAL - 9.8

Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.

Vendor: jizhicms
Product: jizhicms
Published: Apr 23, 2026
Source: NVD
CVE-2026-41460 CRITICAL - 9.8

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerabi...

Vendor: SocialEngine
Product: SocialEngine
Published: Apr 23, 2026
Source: NVD
CVE-2026-39440 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.

Vendor: Funnelforms LLC
Product: FunnelFormsPro
Published: Apr 23, 2026
Source: NVD
CVE-2026-6887 CRITICAL - 9.8

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Published: Apr 23, 2026
Source: NVD
CVE-2026-6886 CRITICAL - 9.8

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.

Published: Apr 23, 2026
Source: NVD
CVE-2026-6885 CRITICAL - 9.8

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Published: Apr 23, 2026
Source: NVD
CVE-2026-41229 CRITICAL - 9.1

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a MySQL server via the AP...

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-41228 CRITICAL - 9.9

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set `def_language` to a path tra...

Vendor: froxlor
Product: froxlor
Published: Apr 23, 2026
Source: NVD
CVE-2026-3844 CRITICAL - 9.8

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-41679 CRITICAL - 10.0

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration....

Vendor: paperclipai
Product: paperclip, @paperclipai/server
Published: Apr 23, 2026
Source: NVD
CVE-2026-41211 CRITICAL - 10.0

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm&g...

Vendor: voidzero-dev
Product: vite-plus
Published: Apr 23, 2026
Source: NVD
CVE-2026-29198 CRITICAL - 9.8

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Apr 23, 2026
Source: NVD
CVE-2026-41167 CRITICAL - 9.1

Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails...

Vendor: CyferShepard
Product: Jellystat
Published: Apr 22, 2026
Source: NVD
CVE-2026-33656 CRITICAL - 9.1

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field on `Attachment` entities. Because `sour...

Vendor: espocrm
Product: espocrm
Published: Apr 22, 2026
Source: NVD