Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,218
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,701 - 1,720 of 22,583 CVEs
CVE-2026-4919 MEDIUM - 4.8

IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2026-4918 MEDIUM - 5.5

IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2026-4917 MEDIUM - 4.9

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2026-40062 HIGH - 7.5

A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the operating system.

Vendor: Ziosoft, Inc.
Product: Ziostation2
Published: Apr 23, 2026
Source: NVD
CVE-2026-3621 HIGH - 7.5

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

Published: Apr 23, 2026
Source: NVD
CVE-2026-32679 HIGH - 7.8

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at th...

Vendor: Japan Media Systems Corporation
Product: Downloader5Installer.exe, Downloader5InstallerForAdmin.exe, CanonNWCamPlugin.exe, CanonNWCamPluginForAdmin.exe
Published: Apr 23, 2026
Source: NVD
CVE-2026-29198 CRITICAL - 9.8

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Apr 23, 2026
Source: NVD
CVE-2026-1726 MEDIUM - 4.8

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1

Vendor: ibm
Product: guardium_key_lifecycle_manager
Published: Apr 23, 2026
Source: NVD
CVE-2026-1352 MEDIUM - 6.5

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow anĀ authenticated user to cause a denial of service due to improper neutralization of specialĀ elements in data query logic.

Vendor: ibm
Product: db2
Published: Apr 23, 2026
Source: NVD
CVE-2026-1274 MEDIUM - 4.9

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2026-1272 LOW - 2.7

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

Vendor: ibm
Product: guardium_data_protection
Published: Apr 23, 2026
Source: NVD
CVE-2025-36074 MEDIUM - 5.5

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against ...

Vendor: IBM
Product: Security Verify Directory (Container)
Published: Apr 23, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Apr 22, 2026
Source: NVD
CVE-2026-41455 HIGH - 8.5

WeKan beforeĀ 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the url schema field accepts any string without protocol restriction or destination validation. Attackers who can create or modify integrations can set webhook URLs to internal network ad...

Vendor: wekan
Product: wekan
Published: Apr 22, 2026
Source: NVD
CVE-2026-41454 HIGH - 8.3

WeKan beforeĀ 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integrations...

Vendor: wekan
Product: wekan
Published: Apr 22, 2026
Source: NVD
CVE-2026-41314 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values. This has been fixed in pypdf 6.10.2....

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41313 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. This has been fixed in pypdf 6.10.2. As ...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41312 MEDIUM - 6.5

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/Predictor` unequal 1 and large predictor...

Vendor: py-pdf
Product: pypdf
Published: Apr 22, 2026
Source: NVD
CVE-2026-41177 MEDIUM - 5.5

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-supplied `Url` parameter, allowing the use...

Vendor: Squidex
Product: squidex
Published: Apr 22, 2026
Source: NVD
CVE-2026-41175 HIGH - 8.1

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requi...

Vendor: statamic
Product: cms
Published: Apr 22, 2026
Source: NVD