Total CVEs

124,065

Critical Severity

2,091

High Severity

7,254

Last 7 Days

1,036
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 1,965 CVEs
CVE-2026-40911 CRITICAL - 10.0

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without sanitizing the `msg` or `callback` fields. On the client side, `plugin/YPTSocket/script.js` contains t...

Vendor: WWBN
Product: AVideo
Published: Apr 21, 2026
Source: NVD
CVE-2026-40906 CRITICAL - 9.9

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORD...

Vendor: electric-sql
Product: electric
Published: Apr 21, 2026
Source: NVD
CVE-2026-34287 CRITICAL - 9.1

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager C...

Published: Apr 21, 2026
Source: NVD
CVE-2026-34286 CRITICAL - 9.1

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager C...

Published: Apr 21, 2026
Source: NVD
CVE-2026-34285 CRITICAL - 9.1

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager C...

Published: Apr 21, 2026
Source: NVD
CVE-2026-34279 CRITICAL - 9.1

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracl...

Published: Apr 21, 2026
Source: NVD
CVE-2026-34275 CRITICAL - 9.8

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracl...

Published: Apr 21, 2026
Source: NVD
CVE-2026-33519 CRITICAL - 9.8

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

Vendor: Esri
Product: Portal for ArcGIS
Published: Apr 21, 2026
Source: NVD
CVE-2026-33518 CRITICAL - 9.8

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.

Vendor: Esri
Product: Portal for ArcGIS
Published: Apr 21, 2026
Source: NVD

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

Vendor: npm
Product: flowise
Published: Apr 21, 2026
Source: GitHub
CVE-2026-40903 CRITICAL - 9.1

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.

Vendor: patrickhener
Product: goshs
Published: Apr 21, 2026
Source: NVD
CVE-2026-40372 CRITICAL - 9.1

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Published: Apr 21, 2026
Source: NVD

Brillig: Heap corruption in foreign call results with nested tuple arrays

Vendor: rust
Product: brillig
Published: Apr 21, 2026
Source: GitHub
CVE-2026-41193 CRITICAL - 9.1

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives without validating file paths, allowing an authenticated admin to write files arbitrarily on the server filesystem via a specially crafted ZIP. V...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-5652 CRITICAL - 9.0

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.

Published: Apr 21, 2026
Source: NVD
CVE-2026-40576 CRITICAL - 9.4

excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated at...

Vendor: haris-musa
Product: excel-mcp-server
Published: Apr 21, 2026
Source: NVD
CVE-2026-40569 CRITICAL - 9.0

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesController.php:468` and `connectionOutgoingSave()` at l...

Vendor: freescout-help-desk
Product: freescout
Published: Apr 21, 2026
Source: NVD
CVE-2026-40050 CRITICAL - 9.8

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability e...

Vendor: CrowdStrike
Product: LogScale Self-Hosted
Published: Apr 21, 2026
Source: NVD
CVE-2025-15638 CRITICAL - 10.0

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

Vendor: ATRODO
Product: Net::Dropbear
Published: Apr 21, 2026
Source: NVD
CVE-2017-20230 CRITICAL - 10.0

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

Vendor: NWCLARK
Product: Storable
Published: Apr 21, 2026
Source: NVD