Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,521 - 1,540 of 3,431 CVEs
CVE-2026-37749 CRITICAL - 9.8

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.

Published: Apr 17, 2026
Source: NVD
CVE-2026-6443 CRITICAL - 9.8

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain...

Published: Apr 17, 2026
Source: NVD
CVE-2026-40322 CRITICAL - 9.0

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks...

Vendor: siyuan-note
Product: siyuan
Published: Apr 16, 2026
Source: NVD
CVE-2026-40933 CRITICAL - 10.0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerabili...

Vendor: npm
Product: flowise
Published: Apr 16, 2026
Source: GitHub
CVE-2026-40324 CRITICAL - 9.1

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list t...

Vendor: nuget
Product: HotChocolate.Language
Published: Apr 16, 2026
Source: GitHub
CVE-2026-33122 CRITICAL - 9.8

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definition is added during a datasource update via /de2api/datasource/update, the deTableName field from the u...

Vendor: dataease
Product: dataease
Published: Apr 16, 2026
Source: NVD
CVE-2026-33082 CRITICAL - 9.8

DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/exportDataset is deserialized into a filtering object and passed to WhereTree2St...

Vendor: dataease
Product: dataease
Published: Apr 16, 2026
Source: NVD
CVE-2026-37347 CRITICAL - 9.1

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37345 CRITICAL - 9.8

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37340 CRITICAL - 9.8

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37339 CRITICAL - 9.8

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37338 CRITICAL - 9.4

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-6270 CRITICAL - 9.1

@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application registers authentication middleware in a parent scope and then registers child plugins with @fastify/middie, the child scope does not inherit the pare...

Vendor: npm
Product: @fastify/middie
Published: Apr 16, 2026
Source: NVD
CVE-2026-31843 CRITICAL - 9.8

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any() without authentication middleware, enabling ...

Vendor: goodoneuz
Product: pay-uz
Published: Apr 16, 2026
Source: NVD
CVE-2026-3596 CRITICAL - 9.8

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the ink_pd_add_option() function. This function reads �...

Published: Apr 16, 2026
Source: NVD
CVE-2026-6350 CRITICAL - 9.8

MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.

Published: Apr 16, 2026
Source: NVD
CVE-2026-40504 CRITICAL - 9.8

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. Attackers can exploit insufficient bounds checking in gravity_fiber_reassign(...

Vendor: marcobambini
Product: gravity
Published: Apr 16, 2026
Source: NVD
CVE-2026-40959 CRITICAL - 9.3

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

Vendor: Luanti
Product: Luanti
Published: Apr 16, 2026
Source: NVD
CVE-2026-32179 CRITICAL - 9.8

MsQuic has a Remote Elevation of Privilege Vulnerability

Vendor: nuget
Product: Microsoft.Native.Quic.MsQuic.OpenSSL
Published: Apr 16, 2026
Source: GitHub
CVE-2026-4880 CRITICAL - 9.8

The Barcode Scanner (+Mobile App) โ€“ Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Bas...

Published: Apr 16, 2026
Source: NVD