Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,994
Quick preset (or use dates below)
Clear Filters
Showing 1,601 - 1,620 of 3,569 CVEs
CVE-2026-4365 CRITICAL - 9.1

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to unauthenticated visit...

Published: Apr 14, 2026
Source: NVD
CVE-2026-27681 CRITICAL - 9.9

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete database data. This leads to a high impact on the confidentiality, integrity, and availability of the s...

Vendor: SAP_SE
Product: SAP Business Planning and Consolidation and SAP Business Warehouse
Published: Apr 14, 2026
Source: NVD
CVE-2026-22564 CRITICAL - 9.8

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitiga...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD
CVE-2026-22563 CRITICAL - 9.8

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
 UniFi Play Audio Port  (Version 1.0.24 and earlier)
 Mitigation: Update UniFi Pla...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD
CVE-2026-22562 CRITICAL - 9.8

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier)
UniFi Play Audio ...

Vendor: Ubiquiti Inc
Product: UniFi Play PowerAmp, UniFi Play Audio Port
Published: Apr 13, 2026
Source: NVD
CVE-2026-31048 CRITICAL - 9.8

An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.

Published: Apr 13, 2026
Source: NVD
CVE-2026-40044 CRITICAL - 9.8

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files with predictable names in the cache directory, which...

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD
CVE-2026-40042 CRITICAL - 9.8

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, c...

Vendor: pancho
Product: Pachno
Published: Apr 13, 2026
Source: NVD
CVE-2026-6195 CRITICAL - 9.8

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be execute...

Published: Apr 13, 2026
Source: NVD

Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in...

Vendor: decidim
Product: decidim
Published: Apr 13, 2026
Source: NVD
CVE-2026-31283 CRITICAL - 9.8

In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Email Bombing attack.

Published: Apr 13, 2026
Source: NVD
CVE-2026-31282 CRITICAL - 9.8

Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker can chain that with missing rate-limit on the login form to launch a brute force attack.

Published: Apr 13, 2026
Source: NVD

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. T...

Vendor: pip
Product: google-adk
Published: Apr 13, 2026
Source: NVD
CVE-2026-5085 CRITICAL - 9.1

Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to the built-in rand() function and the process id. The same method is used in the _generateID method in ...

Published: Apr 13, 2026
Source: NVD
CVE-2026-34865 CRITICAL - 9.1

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Vendor: Huawei
Product: HarmonyOS
Published: Apr 13, 2026
Source: NVD
CVE-2026-6156 CRITICAL - 9.8

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument Comment leads to os command injection. Remote exploitation of the attack is pos...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6155 CRITICAL - 9.8

A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument pppoeServiceName can lead to os command injection. The attack may be launched remotely...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6154 CRITICAL - 9.8

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wizard results in os command injection. The attack may be initiated...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6140 CRITICAL - 9.8

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument FileName results in os command injection. The attack may be initiated remotely. Th...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6139 CRITICAL - 9.8

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The explo...

Published: Apr 13, 2026
Source: NVD