Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,988
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,541 - 1,560 of 3,431 CVEs
CVE-2026-6388 CRITICAL - 9.1

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on ...

Published: Apr 15, 2026
Source: NVD
CVE-2026-40173 CRITICAL - 9.4

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line includ...

Vendor: dgraph-io
Product: dgraph
Published: Apr 15, 2026
Source: NVD
CVE-2026-6296 CRITICAL - 9.6

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: Apr 15, 2026
Source: NVD
CVE-2025-41118 CRITICAL - 9.1

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyr...

Vendor: Grafana
Product: Pyroscope
Published: Apr 15, 2026
Source: NVD
CVE-2026-40478 CRITICAL - 9.1

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neu...

Vendor: maven
Product: org.thymeleaf:thymeleaf
Published: Apr 15, 2026
Source: GitHub
CVE-2026-40477 CRITICAL - 9.1

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restric...

Vendor: maven
Product: org.thymeleaf:thymeleaf
Published: Apr 15, 2026
Source: GitHub
CVE-2026-40575 CRITICAL - 9.1

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so...

Vendor: go
Product: github.com/oauth2-proxy/oauth2-proxy/v7
Published: Apr 15, 2026
Source: GitHub
CVE-2026-30993 CRITICAL - 9.8

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

Published: Apr 15, 2026
Source: NVD
CVE-2026-20186 CRITICAL - 9.9

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerabil...

Vendor: Cisco
Product: Cisco Identity Services Engine Software
Published: Apr 15, 2026
Source: NVD
CVE-2026-20184 CRITICAL - 9.8

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability...

Vendor: Cisco
Product: Cisco Webex Meetings
Published: Apr 15, 2026
Source: NVD
CVE-2026-20180 CRITICAL - 9.9

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerabil...

Vendor: Cisco
Product: Cisco Identity Services Engine Software
Published: Apr 15, 2026
Source: NVD
CVE-2026-20147 CRITICAL - 9.9

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to...

Vendor: Cisco
Product: Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector
Published: Apr 15, 2026
Source: NVD
CVE-2026-30625 CRITICAL - 9.8

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable ex...

Published: Apr 15, 2026
Source: NVD

@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them...

Vendor: @fastify/reply-from
Product: @fastify/reply-from, @fastify/http-proxy
Published: Apr 15, 2026
Source: NVD

Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-scoped authentication middleware via duplicate slashes when ignoreDuplicateSlashes is enabled, or via...

Vendor: fastify
Product: @fastify/express
Published: Apr 15, 2026
Source: NVD
CVE-2026-33807 CRITICAL - 9.1

@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causi...

Vendor: fastify
Product: @fastify/express
Published: Apr 15, 2026
Source: NVD
CVE-2026-3461 CRITICAL - 9.8

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users in based solely on a user-supplied billing email address during guest checkout f...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1555 CRITICAL - 9.8

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server...

Published: Apr 15, 2026
Source: NVD
CVE-2026-39399 CRITICAL - 9.6

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend jobโ€™s handling of .nuspec files within NuGet packages. An attacker can supply a crafted nuspec file with malicious metadata, leading to cross package metadata injection that may r...

Vendor: NuGet
Product: NuGetGallery
Published: Apr 14, 2026
Source: NVD
CVE-2026-35031 CRITICAL - 9.9

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. T...

Vendor: jellyfin
Product: jellyfin
Published: Apr 14, 2026
Source: NVD