Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
Showing 1,461 - 1,480 of 3,561 CVEs
CVE-2026-40911 CRITICAL - 10.0

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without sanitizing the `msg` or `callback` fields. On the client side, `plugin/YPTSocket/script.js` contains t...

Vendor: WWBN
Product: AVideo
Published: Apr 21, 2026
Source: NVD
CVE-2026-40906 CRITICAL - 9.9

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORD...

Vendor: electric-sql
Product: electric
Published: Apr 21, 2026
Source: NVD
CVE-2026-40892 CRITICAL - 9.8

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in PJSIP when using pre-computed digest credentials (PJSIP_CRED_DATA_DIGEST). The function copies credential data using cred_info->data...

Vendor: pjsip
Product: pjproject
Published: Apr 21, 2026
Source: NVD
CVE-2026-34287 CRITICAL - 9.1

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager C...

Vendor: oracle
Product: identity_manager_connector
Published: Apr 21, 2026
Source: NVD
CVE-2026-34286 CRITICAL - 9.1

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager C...

Vendor: oracle
Product: identity_manager_connector
Published: Apr 21, 2026
Source: NVD
CVE-2026-34285 CRITICAL - 9.1

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager C...

Vendor: oracle
Product: identity_manager_connector
Published: Apr 21, 2026
Source: NVD
CVE-2026-34279 CRITICAL - 9.1

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracl...

Vendor: oracle
Product: enterprise_manager_base_platform
Published: Apr 21, 2026
Source: NVD
CVE-2026-34275 CRITICAL - 9.8

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracl...

Vendor: oracle
Product: advanced_inbound_telephony
Published: Apr 21, 2026
Source: NVD
CVE-2026-33519 CRITICAL - 9.8

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

Vendor: Esri
Product: Portal for ArcGIS
Published: Apr 21, 2026
Source: NVD
CVE-2026-33518 CRITICAL - 9.8

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.

Vendor: Esri
Product: Portal for ArcGIS
Published: Apr 21, 2026
Source: NVD
CVE-2026-41264 CRITICAL - 9.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can le...

Vendor: npm
Product: flowise
Published: Apr 21, 2026
Source: GitHub
CVE-2026-40903 CRITICAL - 9.1

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.

Vendor: patrickhener
Product: goshs
Published: Apr 21, 2026
Source: NVD
CVE-2026-40372 CRITICAL - 9.1

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Vendor: nuget
Product: Microsoft.AspNetCore.DataProtection
Published: Apr 21, 2026
Source: NVD

Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode ACIR uses for non-determinism. Noir programs can invoke external functions through foreign calls. When compiling to Brillig bytecode, the SSA instructi...

Vendor: rust
Product: brillig
Published: Apr 21, 2026
Source: GitHub
CVE-2026-41193 CRITICAL - 9.1

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives without validating file paths, allowing an authenticated admin to write files arbitrarily on the server filesystem via a specially crafted ZIP. V...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-5652 CRITICAL - 9.0

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.

Vendor: craftycontrol
Product: crafty_controller
Published: Apr 21, 2026
Source: NVD
CVE-2026-40576 CRITICAL - 9.4

excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated at...

Vendor: haris-musa
Product: excel-mcp-server
Published: Apr 21, 2026
Source: NVD
CVE-2026-40569 CRITICAL - 9.0

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesController.php:468` and `connectionOutgoingSave()` at l...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-40050 CRITICAL - 9.8

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability e...

Vendor: CrowdStrike
Product: LogScale Self-Hosted
Published: Apr 21, 2026
Source: NVD
CVE-2026-38835 CRITICAL - 9.8

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

Vendor: tenda
Product: w30e_firmware
Published: Apr 21, 2026
Source: NVD