Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,218
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,621 - 1,640 of 22,583 CVEs
CVE-2026-40182 MEDIUM - 5.3

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-end/collector over gRPC or HTTP using OpenTelemetry Protocol format (OTLP), if the request results in a unsuccessful request (i.e. HTTP 4xx or 5xx), the response is read into memory...

Vendor: open-telemetry
Product: opentelemetry-dotnet
Published: Apr 23, 2026
Source: NVD
CVE-2026-31533 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto requests"), has a use-after-fre...

Vendor: Linux
Product: Linux
Published: Apr 23, 2026
Source: NVD
CVE-2026-31181 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31179 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-port parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31178 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31177 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31176 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31175 CRITICAL - 9.8

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31174 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31172 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31171 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the url parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31165 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31164 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31160 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-31159 MEDIUM - 6.5

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password parameter to /cgi-bin/cstecgi.cgi.

Vendor: totolink
Product: a3300r_firmware
Published: Apr 23, 2026
Source: NVD
CVE-2026-40472 CRITICAL - 9.9

In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.

Published: Apr 23, 2026
Source: NVD
CVE-2026-40471 CRITICAL - 9.6

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abuse...

Published: Apr 23, 2026
Source: NVD
CVE-2026-40470 CRITICAL - 9.9

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses ...

Published: Apr 23, 2026
Source: NVD
CVE-2026-39087 CRITICAL - 9.8

An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the parseActions function

Published: Apr 23, 2026
Source: NVD
CVE-2026-34003 HIGH - 7.8

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash,...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Apr 23, 2026
Source: NVD