Total CVEs

124,116

Critical Severity

2,092

High Severity

7,265

Last 7 Days

1,051
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 239 CVEs
CVE-2026-35241 MEDIUM - 5.7

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise...

Published: Apr 21, 2026
Source: NVD
CVE-2026-40569 CRITICAL - 9.0

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesController.php:468` and `connectionOutgoingSave()` at l...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-40567 MEDIUM - 5.8

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. The name is stored in the database without sanitization and ...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-39320 HIGH - 7.5

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within the WebSocket subscription handling logic. By injecting unescaped regex metacharacters into the `cont...

Vendor: SignalK
Product: signalk-server
Published: Apr 21, 2026
Source: NVD
CVE-2026-6580 HIGH - 7.3

A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipulation of the argument key leads to use of hard-coded cryptographic key . The attack may be launched...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6577 HIGH - 7.3

A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly ava...

Published: Apr 19, 2026
Source: NVD
CVE-2026-40350 HIGH - 8.8

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator account. This happens because the rout...

Vendor: leepeuker
Product: movary
Published: Apr 18, 2026
Source: NVD
CVE-2026-40349 HIGH - 8.8

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a...

Vendor: leepeuker
Product: movary
Published: Apr 18, 2026
Source: NVD
CVE-2026-40348 HIGH - 7.7

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets through `POST /settings/jellyfin/server-url-verify`. The endpoint accepts a user-controlled URL, appe...

Vendor: leepeuker
Product: movary
Published: Apr 18, 2026
Source: NVD
CVE-2026-33392 HIGH - 7.2

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

Vendor: JetBrains
Product: YouTrack
Published: Apr 17, 2026
Source: NVD
CVE-2026-5797 MEDIUM - 5.3

The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_t...

Published: Apr 17, 2026
Source: NVD
CVE-2026-3488 MEDIUM - 6.5

The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getPrivacyStatus`, `wp_statistics_updatePrivacyStatus`...

Published: Apr 17, 2026
Source: NVD
CVE-2026-40486 MEDIUM - 4.3

Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and internal_rate fields ar...

Vendor: composer
Product: kimai/kimai
Published: Apr 15, 2026
Source: GitHub
CVE-2026-40479 MEDIUM - 5.4

Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team member form prototype...

Vendor: composer
Product: kimai/kimai
Published: Apr 15, 2026
Source: GitHub
CVE-2026-33667 HIGH - 7.4

OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tracking. The existing brute_force_block_after_failed_logins se...

Vendor: opf
Product: openproject
Published: Apr 15, 2026
Source: NVD

Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern directly to Python's re.search() without any timeout or complexity guard. A crafted regex pattern can trigger catastrophic backtrack...

Vendor: pip
Product: giskard-checks
Published: Apr 14, 2026
Source: GitHub
CVE-2026-33657 MEDIUM - 4.6

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into system-generated email notifications by crafting ...

Vendor: espocrm
Product: espocrm
Published: Apr 13, 2026
Source: NVD
CVE-2025-3756 MEDIUM - 6.5

A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing the communication in...

Published: Apr 13, 2026
Source: NVD
CVE-2026-6193 HIGH - 7.3

A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be...

Published: Apr 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp process_sdp() declares union nf_inet_addr rtp_addr on the stack and passes it to the nf_nat_sip sdp_session hook after walking the SDP media description...

Vendor: Linux
Product: Linux
Published: Apr 13, 2026
Source: NVD