Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
Showing 1,481 - 1,500 of 3,561 CVEs
CVE-2026-40498 CRITICAL - 9.8

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APP_KEY, which is exposed in ...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2025-15638 CRITICAL - 10.0

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

Vendor: ATRODO
Product: Net::Dropbear
Published: Apr 21, 2026
Source: NVD
CVE-2017-20230 CRITICAL - 10.0

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

Vendor: NWCLARK
Product: Storable
Published: Apr 21, 2026
Source: NVD
CVE-2026-6771 CRITICAL - 9.8

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Vendor: mozilla
Product: firefox
Published: Apr 21, 2026
Source: NVD
CVE-2026-6768 CRITICAL - 9.8

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Vendor: mozilla
Product: firefox
Published: Apr 21, 2026
Source: NVD
CVE-2026-6760 CRITICAL - 9.8

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Vendor: mozilla
Product: firefox
Published: Apr 21, 2026
Source: NVD
CVE-2026-6748 CRITICAL - 9.8

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Vendor: mozilla
Product: firefox
Published: Apr 21, 2026
Source: NVD
CVE-2026-5965 CRITICAL - 9.8

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Published: Apr 21, 2026
Source: NVD
CVE-2026-40496 CRITICAL - 9.1

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthenti...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-41329 CRITICAL - 9.9

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper context validation to bypass sandbox restrictions and achieve unauthorized privilege ...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 21, 2026
Source: NVD
CVE-2026-5450 CRITICAL - 9.8

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Vendor: gnu
Product: glibc
Published: Apr 20, 2026
Source: NVD
CVE-2026-5358 CRITICAL - 9.1

Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API provisional and unused. Secondly it has been discovered that the NIS+ cold start c...

Published: Apr 20, 2026
Source: NVD
CVE-2026-33432 CRITICAL - 9.1

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the filter string without esca...

Vendor: roxy-wi
Product: roxy-wi
Published: Apr 20, 2026
Source: NVD
CVE-2026-32613 CRITICAL - 9.9

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restr...

Vendor: spinnaker
Product: spinnaker
Published: Apr 20, 2026
Source: NVD
CVE-2026-32604 CRITICAL - 9.9

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026...

Vendor: spinnaker
Product: spinnaker
Published: Apr 20, 2026
Source: NVD
CVE-2026-29646 CRITICAL - 9.8

In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6257 CRITICAL - 9.1

Vvveb CMS v1.0.8 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php or .htaccess. Attackers can exploit this logic flaw by first upl...

Published: Apr 20, 2026
Source: NVD
CVE-2026-32311 CRITICAL - 9.8

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relat...

Vendor: reconurge
Product: flowsint
Published: Apr 20, 2026
Source: NVD
CVE-2026-29649 CRITICAL - 9.8

NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/updated based on menvcfg[7:4], so a machine-mode write to menvcfg can implicitly modify the hypervisor's environment configuration. This can lead ...

Vendor: xiangshan
Product: nemu
Published: Apr 20, 2026
Source: NVD
CVE-2026-39109 CRITICAL - 9.4

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database c...

Published: Apr 20, 2026
Source: NVD