Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,853
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,481 - 1,500 of 3,421 CVEs
CVE-2026-32604 CRITICAL - 9.9

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026...

Vendor: spinnaker
Product: spinnaker
Published: Apr 20, 2026
Source: NVD
CVE-2026-29646 CRITICAL - 9.8

In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6257 CRITICAL - 9.1

Vvveb CMS v1.0.8 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php or .htaccess. Attackers can exploit this logic flaw by first upl...

Published: Apr 20, 2026
Source: NVD
CVE-2026-32311 CRITICAL - 9.8

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relat...

Vendor: reconurge
Product: flowsint
Published: Apr 20, 2026
Source: NVD
CVE-2026-29649 CRITICAL - 9.8

NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/updated based on menvcfg[7:4], so a machine-mode write to menvcfg can implicitly modify the hypervisor's environment configuration. This can lead ...

Vendor: xiangshan
Product: nemu
Published: Apr 20, 2026
Source: NVD
CVE-2026-39109 CRITICAL - 9.4

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database c...

Published: Apr 20, 2026
Source: NVD
CVE-2026-30269 CRITICAL - 9.9

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privil...

Vendor: doorman
Product: doorman
Published: Apr 20, 2026
Source: NVD
CVE-2026-39918 CRITICAL - 9.8

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the string context in the ...

Vendor: givanz
Product: Vvveb
Published: Apr 20, 2026
Source: NVD
CVE-2026-24467 CRITICAL - 9.0

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's password reset implementation contains multiple security weaknesses that together allow reliabl...

Vendor: OpenAEV-Platform
Product: openaev
Published: Apr 20, 2026
Source: NVD
CVE-2026-5760 CRITICAL - 9.8

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

Published: Apr 20, 2026
Source: NVD
CVE-2026-33557 CRITICAL - 9.1

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience....

Vendor: Apache Software Foundation
Product: Apache Kafka
Published: Apr 20, 2026
Source: NVD
CVE-2026-5964 CRITICAL - 9.8

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Published: Apr 20, 2026
Source: NVD
CVE-2026-5963 CRITICAL - 9.8

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Published: Apr 20, 2026
Source: NVD
CVE-2026-6644 CRITICAL - 9.1

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied in...

Vendor: asustor
Product: data_master
Published: Apr 20, 2026
Source: NVD
CVE-2026-6643 CRITICAL - 9.9

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an authenticated remote attacker can exploit these to ex...

Vendor: asustor
Product: data_master
Published: Apr 20, 2026
Source: NVD
CVE-2026-32956 CRITICAL - 9.8

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

Vendor: silex technology, Inc.
Product: SD-330AC, AMC Manager
Published: Apr 20, 2026
Source: NVD
CVE-2026-41242 CRITICAL - 9.8

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 pa...

Vendor: protobufjs
Product: protobuf.js
Published: Apr 18, 2026
Source: NVD
CVE-2026-25917 CRITICAL - 9.8

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, whic...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 18, 2026
Source: NVD
CVE-2026-40494 CRITICAL - 9.8

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's RLE decoder in `tga.c` has an asymmetric bounds check vulnerability. The run-packet path (line 297) co...

Vendor: HappySeaFox
Product: sail
Published: Apr 18, 2026
Source: NVD
CVE-2026-40493 CRITICAL - 9.8

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec computes bytes-per-pixel (`bpp`) from raw header fields `channels * depth`, but the pixel buffer is allocated...

Vendor: HappySeaFox
Product: sail
Published: Apr 18, 2026
Source: NVD