Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,701 - 1,720 of 3,435 CVEs
CVE-2026-31017 CRITICAL - 9.1

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application al...

Vendor: frappe
Product: erpnext
Published: Apr 08, 2026
Source: NVD
CVE-2023-46945 CRITICAL - 9.1

QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

Vendor: qd-today
Product: qd
Published: Apr 08, 2026
Source: NVD
CVE-2026-39640 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.

Vendor: mndpsingh287
Product: Theme Editor
Published: Apr 08, 2026
Source: NVD
CVE-2026-39620 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.

Vendor: priyanshumittal
Product: Appointment
Published: Apr 08, 2026
Source: NVD
CVE-2026-39619 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.

Vendor: priyanshumittal
Product: Busiprof
Published: Apr 08, 2026
Source: NVD
CVE-2026-39617 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.

Vendor: priyanshumittal
Product: Bluestreet
Published: Apr 08, 2026
Source: NVD
CVE-2026-25776 CRITICAL - 9.8

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

Vendor: Six Apart Ltd.
Product: Movable Type, Movable Type Advanced, Movable Type Premium, Movable Type Premium Advanced Edition, Movable Type Premium (MT8-based)
Published: Apr 08, 2026
Source: NVD
CVE-2026-3535 CRITICAL - 9.8

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4003 CRITICAL - 9.8

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function within the 'userspn_form_save' case. T...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3296 CRITICAL - 9.8

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry m...

Published: Apr 08, 2026
Source: NVD
CVE-2026-27143 CRITICAL - 9.8

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Vendor: Go toolchain
Product: cmd/compile
Published: Apr 08, 2026
Source: NVD
CVE-2026-1346 CRITICAL - 9.3

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to roo...

Vendor: ibm
Product: security_verify_access
Published: Apr 08, 2026
Source: NVD
CVE-2026-39847 CRITICAL - 9.1

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attacker can use ../ sequences (eg /__emmett__/../rsgi/handlers.py) to read arbi...

Vendor: emmett-framework
Product: emmett
Published: Apr 07, 2026
Source: NVD
CVE-2026-39846 CRITICAL - 9.0

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, crea...

Vendor: siyuan-note
Product: siyuan
Published: Apr 07, 2026
Source: NVD
CVE-2026-28386 CRITICAL - 9.1

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for ...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-39397 CRITICAL - 9.4

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control....

Vendor: delmaredigital
Product: payload-puck
Published: Apr 07, 2026
Source: NVD
CVE-2025-69515 CRITICAL - 9.1

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

Published: Apr 07, 2026
Source: NVD
CVE-2026-39355 CRITICAL - 9.9

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces an...

Vendor: MGeurts
Product: genealogy
Published: Apr 07, 2026
Source: NVD
CVE-2026-39351 CRITICAL - 9.1

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

Vendor: frappe
Product: frappe
Published: Apr 07, 2026
Source: NVD
CVE-2025-71058 CRITICAL - 9.1

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject ...

Published: Apr 07, 2026
Source: NVD