Total CVEs

123,901

Critical Severity

2,072

High Severity

7,209

Last 7 Days

893
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 802 CVEs
CVE-2026-6743 LOW - 3.5

A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading the affected component...

Published: Apr 21, 2026
Source: NVD

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in src/bacnet/bacint.c reconstructs a 32-bit signed integer from four APDU bytes using signed left shifts. When any of the four bytes has bit 7 set (value โ‰ฅ 0x80), the left-shift ope...

Vendor: bacnet-stack
Product: bacnet-stack
Published: Apr 21, 2026
Source: NVD

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor extensions. This only affects backend users who were explicitly granted editor access b...

Vendor: octobercms
Product: october
Published: Apr 21, 2026
Source: NVD

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. This vulnerability is fixed in 3.7.16 an...

Vendor: octobercms
Product: october
Published: Apr 21, 2026
Source: NVD

HCL BigFix Service Management is susceptible to HTTP Request Smuggling.ย  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end server...

Vendor: HCLSoftware
Product: BigFix Service Management (SM)
Published: Apr 21, 2026
Source: NVD

PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability

Vendor: Honor
Product: PcManager
Published: Apr 21, 2026
Source: NVD

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5...

Vendor: openbao
Product: openbao
Published: Apr 21, 2026
Source: NVD

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decompressed tar data via `io.Copy` with no upper bound on the number of bytes w...

Vendor: openbao
Product: openbao
Published: Apr 21, 2026
Source: NVD

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's presented mTLS certificate matches the orig...

Vendor: openbao
Product: openbao
Published: Apr 21, 2026
Source: NVD
CVE-2026-6651 LOW - 2.4

A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The attack may be launched remotely. The exploit has been releas...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6648 LOW - 3.5

A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. The ven...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6633 LOW - 3.5

A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php of the component Extended Management Module. The manipulation of the argument Account results in cross site scripting. The...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6624 LOW - 2.4

A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been ...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6623 LOW - 2.4

A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible to be carried out rem...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6622 LOW - 2.4

A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit is publicly availa...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6619 LOW - 3.5

A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePreview. The manipulation of the argument filename leads to cross site scripting. The attack may be initiat...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6611 LOW - 3.1

A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulation of the argument SECRET_KEY results in use of hard-coded cryptographic key . Remote exploitation of...

Published: Apr 20, 2026
Source: NVD
CVE-2024-7083 LOW - 3.5

The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Published: Apr 20, 2026
Source: NVD
CVE-2026-6610 LOW - 3.7

A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads to hard-coded credentials. The attack may be launched remote...

Published: Apr 20, 2026
Source: NVD
CVE-2026-6600 LOW - 3.5

A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Frontend React Component Rendering. Executing a manipulation can lead to cross site scr...

Published: Apr 20, 2026
Source: NVD