Total CVEs

125,793

Critical Severity

2,272

High Severity

7,857

Last 7 Days

1,137
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 7,857 CVEs

Clerk has an authorization bypass when combining organization, billing, or reverification checks

Vendor: npm
Product: @clerk/shared
Published: Apr 30, 2026
Source: GitHub
CVE-2026-33845 HIGH - 7.5

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Apr 30, 2026
Source: NVD
CVE-2026-42449 HIGH - 8.5

n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders

Vendor: npm
Product: n8n-mcp
Published: Apr 30, 2026
Source: GitHub

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

Vendor: npm
Product: @jupyter-notebook/help-extension
Published: Apr 30, 2026
Source: GitHub
CVE-2026-39383 HIGH - 8.6

Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: Apr 30, 2026
Source: GitHub
CVE-2025-51846 HIGH - 7.5

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.

Vendor: CryptPad
Product: CryptPad
Published: Apr 30, 2026
Source: NVD
CVE-2022-50992 HIGH - 7.5

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowServi...

Vendor: Weaver Network Co., Ltd.
Product: E-cology
Published: Apr 30, 2026
Source: NVD
CVE-2026-5174 HIGH - 7.7

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Published: Apr 30, 2026
Source: NVD
CVE-2026-36960 HIGH - 8.8

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a...

Published: Apr 30, 2026
Source: NVD
CVE-2026-36340 HIGH - 8.1

An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

Published: Apr 30, 2026
Source: NVD
CVE-2026-36959 HIGH - 7.5

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized ...

Published: Apr 30, 2026
Source: NVD
CVE-2026-36958 HIGH - 7.5

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the ro...

Published: Apr 30, 2026
Source: NVD
CVE-2026-36957 HIGH - 7.5

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffer...

Published: Apr 30, 2026
Source: NVD
CVE-2026-36956 HIGH - 8.8

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An a...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7246 HIGH - 7.2

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

Vendor: palletsprojects
Product: click
Published: Apr 30, 2026
Source: NVD
CVE-2026-2892 HIGH - 7.5

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated u...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7402 HIGH - 8.1

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Published: Apr 30, 2026
Source: NVD
CVE-2026-7399 HIGH - 8.1

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Published: Apr 30, 2026
Source: NVD
CVE-2026-41882 HIGH - 7.4

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

Vendor: JetBrains
Product: IntelliJ IDEA
Published: Apr 30, 2026
Source: NVD
CVE-2026-42800 HIGH - 7.4

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

Vendor: ASR
Product: Lapwing_Linux
Published: Apr 30, 2026
Source: NVD