Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
Showing 1,701 - 1,720 of 3,569 CVEs
CVE-2026-5874 CRITICAL - 9.6

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-40035 CRITICAL - 9.1

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the...

Vendor: obsidianforensics
Product: unfurl
Published: Apr 08, 2026
Source: NVD
CVE-2026-40088 CRITICAL - 9.7

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls, allowing attackers to inject arbitrary shell commands through shell metachara...

Vendor: pip
Product: PraisonAI
Published: Apr 08, 2026
Source: GitHub

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket ...

Vendor: pip
Product: marimo
Published: Apr 08, 2026
Source: GitHub
CVE-2026-39890 CRITICAL - 9.8

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an attacker to craft a malicious YAML file that, when parsed, exe...

Vendor: MervinPraison
Product: PraisonAI
Published: Apr 08, 2026
Source: NVD
CVE-2026-39888 CRITICAL - 9.9

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted __builtins__ dict and an AST-based blocklist. The AST blocklist embedded inside...

Vendor: MervinPraison
Product: praisonaiagents
Published: Apr 08, 2026
Source: NVD
CVE-2026-39860 CRITICAL - 9.0

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-outp...

Vendor: NixOS
Product: nix
Published: Apr 08, 2026
Source: NVD
CVE-2026-2942 CRITICAL - 9.8

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-31017 CRITICAL - 9.1

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application al...

Vendor: frappe
Product: erpnext
Published: Apr 08, 2026
Source: NVD
CVE-2023-46945 CRITICAL - 9.1

QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

Vendor: qd-today
Product: qd
Published: Apr 08, 2026
Source: NVD
CVE-2026-39640 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.

Vendor: mndpsingh287
Product: Theme Editor
Published: Apr 08, 2026
Source: NVD
CVE-2026-39620 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.

Vendor: priyanshumittal
Product: Appointment
Published: Apr 08, 2026
Source: NVD
CVE-2026-39619 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.

Vendor: priyanshumittal
Product: Busiprof
Published: Apr 08, 2026
Source: NVD
CVE-2026-39617 CRITICAL - 9.6

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.

Vendor: priyanshumittal
Product: Bluestreet
Published: Apr 08, 2026
Source: NVD
CVE-2026-25776 CRITICAL - 9.8

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

Vendor: Six Apart Ltd.
Product: Movable Type, Movable Type Advanced, Movable Type Premium, Movable Type Premium Advanced Edition, Movable Type Premium (MT8-based)
Published: Apr 08, 2026
Source: NVD
CVE-2026-3535 CRITICAL - 9.8

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4003 CRITICAL - 9.8

The Users manager โ€“ PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function within the 'userspn_form_save' case. T...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3296 CRITICAL - 9.8

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry m...

Published: Apr 08, 2026
Source: NVD
CVE-2026-27143 CRITICAL - 9.8

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Vendor: Go toolchain
Product: cmd/compile
Published: Apr 08, 2026
Source: NVD
CVE-2026-1346 CRITICAL - 9.3

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to roo...

Vendor: ibm
Product: security_verify_access
Published: Apr 08, 2026
Source: NVD