Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,903
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,621 - 1,640 of 3,431 CVEs
CVE-2026-5058 CRITICAL - 9.8

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the a...

Published: Apr 11, 2026
Source: NVD
CVE-2026-4149 CRITICAL - 10.0

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not required to exploit this vulnerability. The specific flaw exists within the han...

Vendor: sonos
Product: era_300_firmware
Published: Apr 11, 2026
Source: NVD
CVE-2026-40258 CRITICAL - 9.1

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature. An authenticated user with owner-level privileges can craft a malicious ZIP file with directory-tra...

Vendor: pip
Product: gramps-webapi
Published: Apr 10, 2026
Source: GitHub
CVE-2026-40189 CRITICAL - 9.8

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload fi...

Vendor: patrickhener
Product: goshs
Published: Apr 10, 2026
Source: NVD

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.

Vendor: ajenti
Product: ajenti
Published: Apr 10, 2026
Source: NVD
CVE-2026-40175 CRITICAL - 10.0

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Comp...

Vendor: axios
Product: axios
Published: Apr 10, 2026
Source: NVD
CVE-2026-30232 CRITICAL - 9.6

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches these URLs using request-promise without any IP a...

Vendor: chartbrew
Product: chartbrew
Published: Apr 10, 2026
Source: NVD
CVE-2026-33707 CRITICAL - 9.4

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the v...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 10, 2026
Source: NVD
CVE-2026-33698 CRITICAL - 9.8

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals wit...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 10, 2026
Source: NVD
CVE-2026-32892 CRITICAL - 9.1

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshe...

Vendor: chamilo
Product: chamilo-lms
Published: Apr 10, 2026
Source: NVD

PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without validating archive member paths. A .praison bundle containing ../../ entries will write files outside the intended output directory. An attacker who ...

Vendor: MervinPraison
Product: PraisonAI
Published: Apr 10, 2026
Source: NVD
CVE-2026-23781 CRITICAL - 9.8

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface.

Published: Apr 10, 2026
Source: NVD
CVE-2026-36236 CRITICAL - 9.8

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

Vendor: janobe
Product: engineers_online_portal
Published: Apr 10, 2026
Source: NVD
CVE-2026-36235 CRITICAL - 9.8

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-36234 CRITICAL - 9.8

itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-36233 CRITICAL - 9.8

A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for...

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-36232 CRITICAL - 9.8

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or...

Vendor: itsourcecode
Product: online_student_enrollment_system
Published: Apr 10, 2026
Source: NVD
CVE-2026-29861 CRITICAL - 9.8

PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.

Published: Apr 10, 2026
Source: NVD
CVE-2025-44560 CRITICAL - 9.8

owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.

Published: Apr 10, 2026
Source: NVD
CVE-2026-5412 CRITICAL - 9.9

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issu...

Vendor: go
Product: github.com/juju/juju
Published: Apr 10, 2026
Source: NVD